Record summary

CVE-2024-38573 has a selected CVSS score of 7.5 (high).

Description

In the Linux kernel, the following vulnerability has been resolved: cppc_cpufreq: Fix possible null pointer dereference cppc_cpufreq_get_rate() and hisi_cppc_cpufreq_get_rate() can be called from different places with various parameters. So cpufreq_cpu_get() can return null as 'policy' in some circumstances. Fix this bug by adding null return check. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 27, 2024 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus

Default status: unaffected, affected

CVE Lista28b2bfc099c6b9caa6ef697660408e076a32019 to < 9a185cc5a79ba408e1c73375706630662304f618affected
a28b2bfc099c6b9caa6ef697660408e076a32019 to < 769c4f355b7962895205b86ad35617873feef9a5affected
a28b2bfc099c6b9caa6ef697660408e076a32019 to < f84b9b25d045e67a7eee5e73f21278c8ab06713caffected
a28b2bfc099c6b9caa6ef697660408e076a32019 to < b18daa4ec727c0266de5bfc78e818d168cc4aedfaffected
a28b2bfc099c6b9caa6ef697660408e076a32019 to < dfec15222529d22b15e5b0d63572a9e39570cab4affected
a28b2bfc099c6b9caa6ef697660408e076a32019 to < cf7de25878a1f4508c69dc9f6819c21ba177dbfeaffected
5.11affected
Before 5.11unaffected
5.15.161 to ≤ 5.15.*unaffected
6.1.93 to ≤ 6.1.*unaffected
6.6.33 to ≤ 6.6.*unaffected
6.8.12 to ≤ 6.8.*unaffected
Showing 12 of 14 version ranges

Default status: unknown

CVE Lista28b2bfc099c to < cf7de25878a1affected

Default status: unknown

CVE Lista28b2bfc099c to < 9a185cc5a79baffected
a28b2bfc099c to < 769c4f355b79affected
6.6.33 to ≤ 6.7unaffected
6.8.12 to ≤ 6.9unaffected
6.9.3 to ≤ 6.10unaffected
6.10-rc1unaffected
a28b2bfc099c to < f84b9b25d045affected
a28b2bfc099c to < b18daa4ec727affected
a28b2bfc099c to < dfec15222529affected
5.11affected
Before 5.11unaffected
5.15.161 to ≤ 5.16unaffected
Showing 12 of 13 version ranges
OSV5.11.0 to < 5.15.161 · Fixed in 5.15.161affected
5.16.0 to < 6.1.93 · Fixed in 6.1.93affected
6.2.0 to < 6.6.33 · Fixed in 6.6.33affected
6.7.0 to < 6.8.12 · Fixed in 6.8.12affected
6.9.0 to < 6.9.3 · Fixed in 6.9.3affected

References

9