cbcvebase.
CVE-2024-27037
published 2024-05-01

CVE-2024-27037: In the Linux kernel, the following vulnerability has been resolved: clk: zynq: Prevent null pointer dereference caused by kmalloc failure The kmalloc() in…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
19.4th percentile
In the Linux kernel, the following vulnerability has been resolved: clk: zynq: Prevent null pointer dereference caused by kmalloc failure The kmalloc() in zynq_clk_setup() will return null if the physical memory has run out. As a result, if we use snprintf() to write data to the null address, the null pointer dereference bug will happen. This patch uses a stack variable to replace the kmalloc().

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= 0ee52b157b8ed88550ddd6291e54bb4bfabde364 < 01511ac7be8e45f80e637f6bf61af2d3d2dee9db01511ac7be8e45f80e637f6bf61af2d3d2dee9db
linuxlinux>= 0ee52b157b8ed88550ddd6291e54bb4bfabde364 < 8c4889a9ea861d7be37463c10846eb75e1b49c9d8c4889a9ea861d7be37463c10846eb75e1b49c9d
linuxlinux>= 0ee52b157b8ed88550ddd6291e54bb4bfabde364 < 0801c893fd48cdba66a3c8f44c3fe43cc67d3b850801c893fd48cdba66a3c8f44c3fe43cc67d3b85
linuxlinux>= 0ee52b157b8ed88550ddd6291e54bb4bfabde364 < ca976c6a592f789700200069ef9052493c0b73d8ca976c6a592f789700200069ef9052493c0b73d8
linuxlinux>= 0ee52b157b8ed88550ddd6291e54bb4bfabde364 < 58a946ab43501f2eba058d24d96af0ad1122475b58a946ab43501f2eba058d24d96af0ad1122475b
linuxlinux>= 0ee52b157b8ed88550ddd6291e54bb4bfabde364 < 7938e9ce39d6779d2f85d822cc930f73420e54a67938e9ce39d6779d2f85d822cc930f73420e54a6
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 3.11 < 5.15.1535.15.153
linuxlinux_kernel>= 5.16 < 6.1.836.1.83
linuxlinux_kernel>= 6.2 < 6.6.236.6.23
linuxlinux_kernel>= 6.7 < 6.7.116.7.11
linuxlinux_kernel>= 6.8 < 6.8.26.8.2
msrcazl3_hyperv-daemons_6.6.22.1-2_on_azure_linux_3.0
msrcazl3_hyperv-daemons_6.6.29.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.