cbcvebase.
CVE-2024-39466
published 2024-06-25

CVE-2024-39466: In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/qcom/lmh: Check for SCM availability at probe Up until now, the necessary…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.7th percentile
In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/qcom/lmh: Check for SCM availability at probe Up until now, the necessary scm availability check has not been performed, leading to possible null pointer dereferences (which did happen for me on RB1). Fix that.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= 53bca371cdf7addc1e93e1b99285b3d3935685ec < 2226b145afa5e13cb60dbe77fb20fb0666a1caf32226b145afa5e13cb60dbe77fb20fb0666a1caf3
linuxlinux>= 53bca371cdf7addc1e93e1b99285b3d3935685ec < 560d69c975072974c11434ca6953891e74c1a665560d69c975072974c11434ca6953891e74c1a665
linuxlinux>= 53bca371cdf7addc1e93e1b99285b3d3935685ec < 0a47ba94ec3d8f782b33e3d970cfcb769b9624640a47ba94ec3d8f782b33e3d970cfcb769b962464
linuxlinux>= 53bca371cdf7addc1e93e1b99285b3d3935685ec < aa1a0807b4a76b44fb6b58a7e9087cd4b18ab41baa1a0807b4a76b44fb6b58a7e9087cd4b18ab41b
linuxlinux>= 53bca371cdf7addc1e93e1b99285b3d3935685ec < d9d3490c48df572edefc0b64655259eefdcbb9bed9d3490c48df572edefc0b64655259eefdcbb9be
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 5.15 < 5.15.1615.15.161
linuxlinux_kernel>= 5.16 < 6.1.946.1.94
linuxlinux_kernel>= 6.2 < 6.6.346.6.34
linuxlinux_kernel>= 6.7 < 6.9.56.9.5

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.