cbcvebase.
CVE-2024-27028
published 2024-05-01

CVE-2024-27028: In the Linux kernel, the following vulnerability has been resolved: spi: spi-mt65xx: Fix NULL pointer access in interrupt handler The TX buffer in spi_transfer…

PriorityP433medium6.5CVSS 3.1
AVNACLPRNUINSUCNILAL
EPSS
1.18%
64.5th percentile
In the Linux kernel, the following vulnerability has been resolved: spi: spi-mt65xx: Fix NULL pointer access in interrupt handler The TX buffer in spi_transfer can be a NULL pointer, so the interrupt handler may end up writing to the invalid memory and cause crashes. Add a check to trans->tx_buf before using it.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= 1ce24864bff40e11500a699789412115fdf244bf < 2342b05ec5342a519e00524a507f7a6ea6791a382342b05ec5342a519e00524a507f7a6ea6791a38
linuxlinux>= 1ce24864bff40e11500a699789412115fdf244bf < 55f8ea6731aa64871ee6aef7dba53ee9f9f3b2f655f8ea6731aa64871ee6aef7dba53ee9f9f3b2f6
linuxlinux>= 1ce24864bff40e11500a699789412115fdf244bf < bcfcdf19698024565eff427706ebbd8df65abd11bcfcdf19698024565eff427706ebbd8df65abd11
linuxlinux>= 1ce24864bff40e11500a699789412115fdf244bf < c10fed329c1c104f375a75ed97ea3abef0786d62c10fed329c1c104f375a75ed97ea3abef0786d62
linuxlinux>= 1ce24864bff40e11500a699789412115fdf244bf < 766ec94cc57492eab97cbbf1595bd516ab0cb0e4766ec94cc57492eab97cbbf1595bd516ab0cb0e4
linuxlinux>= 1ce24864bff40e11500a699789412115fdf244bf < 62b1f837b15cf3ec2835724bdf8577e47d14c75362b1f837b15cf3ec2835724bdf8577e47d14c753
linuxlinux>= 1ce24864bff40e11500a699789412115fdf244bf < bea82355df9e1c299625405b1947fc9b26b4c6d4bea82355df9e1c299625405b1947fc9b26b4c6d4
linuxlinux>= 1ce24864bff40e11500a699789412115fdf244bf < 1784053cf10a14c4ebd8a890bad5cfe1bee517131784053cf10a14c4ebd8a890bad5cfe1bee51713
linuxlinux>= 1ce24864bff40e11500a699789412115fdf244bf < a20ad45008a7c82f1184dc6dee280096009ece55a20ad45008a7c82f1184dc6dee280096009ece55
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 4.11 < 4.19.3114.19.311
linuxlinux_kernel>= 4.20 < 5.4.2735.4.273
linuxlinux_kernel>= 5.11 < 5.15.1535.15.153
linuxlinux_kernel>= 5.16 < 6.1.836.1.83
linuxlinux_kernel>= 5.5 < 5.10.2145.10.214
linuxlinux_kernel>= 6.2 < 6.6.236.6.23

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.