Lucene search

K
redhatcveRedhat.comRH:CVE-2024-43833
HistoryAug 19, 2024 - 1:15 p.m.

CVE-2024-43833

2024-08-1913:15:59
redhat.com
access.redhat.com
6
linux
kernel
vulnerability
null pointer dereference
ancillary links

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

5.4

Confidence

High

EPSS

0

Percentile

5.0%

A flaw was found in the v4l2-async module in the Linux kernel. Adding ancillary links with a NULL source sub-device can cause a NULL pointer dereference, resulting in a denial of service.

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

5.4

Confidence

High

EPSS

0

Percentile

5.0%