Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-38573
HistoryJun 19, 2024 - 12:00 a.m.

CVE-2024-38573

2024-06-1900:00:00
ubuntu.com
ubuntu.com
2
linux kernel
vulnerability
null pointer dereference
cppc_cpufreq
hisi_cppc_cpufreq_get_rate
cpufreq_cpu_get
null return check
linux verification center
svace
unix

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the Linux kernel, the following vulnerability has been resolved:
cppc_cpufreq: Fix possible null pointer dereference cppc_cpufreq_get_rate()
and hisi_cppc_cpufreq_get_rate() can be called from different places with
various parameters. So cpufreq_cpu_get() can return null as ‘policy’ in
some circumstances. Fix this bug by adding null return check. Found by
Linux Verification Center (linuxtesting.org) with SVACE.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H