CVE-2024-27025NULL Pointer Dereference in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 99.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 1

Description

In the Linux kernel, the following vulnerability has been resolved: nbd: null check for nla_nest_start nla_nest_start() may fail and return NULL. Insert a check and set errno based on other call sites within the same source code.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel4.125.4.273+6
Debianlinux/linux_kernel< 5.10.216-1+3
CVEListV5linux/linux47d902b90a32a42a3d33aef3a02170fc6f70aa2344214d744be32a4769faebba764510888f1eb19e+8
debiandebian/linux< linux 6.1.85-1 (bookworm)

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

2
OSV
CVE-2024-27025: In the Linux kernel, the following vulnerability has been resolved: nbd: null check for nla_nest_start nla_nest_start() may fail and return NULL2024-05-01
GHSA
GHSA-gmgh-9qgw-5r7q: In the Linux kernel, the following vulnerability has been resolved: nbd: null check for nla_nest_start nla_nest_start() may fail and return NULL2024-05-01

📋Vendor Advisories

2
Red Hat
kernel: nbd: null check for nla_nest_start2024-05-01
Debian
CVE-2024-27025: linux - In the Linux kernel, the following vulnerability has been resolved: nbd: null c...2024

💬Community

1
Bugzilla
CVE-2024-27025 kernel: nbd: null check for nla_nest_start2024-05-01