cbcvebase.
CVE-2024-38584
published 2024-06-19

CVE-2024-38584: In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg_prueth: Fix NULL pointer dereference in prueth_probe() In the prueth_probe()…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.2th percentile
In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg_prueth: Fix NULL pointer dereference in prueth_probe() In the prueth_probe() function, if one of the calls to emac_phy_connect() fails due to of_phy_connect() returning NULL, then the subsequent call to phy_attached_info() will dereference a NULL pointer. Check the return code of emac_phy_connect and fail cleanly if there is an error.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.8.12-1 (forky)linux 6.8.12-1 (forky)
linuxlinux
linuxlinux>= 128d5874c0822105ae9556d5435fb8562aff2e3b < 5cd17f0e74cb99d209945b9f1f06d411aa667eb15cd17f0e74cb99d209945b9f1f06d411aa667eb1
linuxlinux>= 128d5874c0822105ae9556d5435fb8562aff2e3b < b0a82ebabbdc4c307f781bb0e5cd617949a3900db0a82ebabbdc4c307f781bb0e5cd617949a3900d
linuxlinux>= 128d5874c0822105ae9556d5435fb8562aff2e3b < 1e1d5bd7f4682e6925dd960aba2a1aa1d93da53a1e1d5bd7f4682e6925dd960aba2a1aa1d93da53a
linuxlinux>= 128d5874c0822105ae9556d5435fb8562aff2e3b < b31c7e78086127a7fcaa761e8d336ee855a920c6b31c7e78086127a7fcaa761e8d336ee855a920c6
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 6.6 < 6.6.336.6.33
linuxlinux_kernel>= 6.7 < 6.8.126.8.12
linuxlinux_kernel>= 6.9 < 6.9.36.9.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.