Lucene search

K
vulnrichmentLinuxVULNRICHMENT:CVE-2024-39470
HistoryJun 25, 2024 - 2:28 p.m.

CVE-2024-39470 eventfs: Fix a possible null pointer dereference in eventfs_find_events()

2024-06-2514:28:56
Linux
github.com
3
cve-2024-39470
eventfs
null pointer

AI Score

6.8

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

In the Linux kernel, the following vulnerability has been resolved:

eventfs: Fix a possible null pointer dereference in eventfs_find_events()

In function eventfs_find_events,there is a potential null pointer
that may be caused by calling update_events_attr which will perform
some operations on the members of the ei struct when ei is NULL.

Hence,When ei->is_freed is set,return NULL directly.

AI Score

6.8

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial