cbcvebase.
CVE-2024-39470
published 2024-06-25

CVE-2024-39470: In the Linux kernel, the following vulnerability has been resolved: eventfs: Fix a possible null pointer dereference in eventfs_find_events() In function…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.7th percentile
In the Linux kernel, the following vulnerability has been resolved: eventfs: Fix a possible null pointer dereference in eventfs_find_events() In function eventfs_find_events,there is a potential null pointer that may be caused by calling update_events_attr which will perform some operations on the members of the ei struct when ei is NULL. Hence,When ei->is_freed is set,return NULL directly.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.9.7-1 (forky)linux 6.9.7-1 (forky)
linuxlinux
linuxlinux
linuxlinux>= 6.6.18 < 6.6.346.6.34
linuxlinux>= 6.7.4 < 6.86.8
linuxlinux>= 628adb842bd5e1c2c598534a7a022b8235289de6 < 5ade5fbdbbb1f023bb70730ba4d74146c8bc7eb95ade5fbdbbb1f023bb70730ba4d74146c8bc7eb9
linuxlinux>= 8186fff7ab649085e2c60d032d9a20a85af1d87c < 7a1b2d138189375ed1dcd7d0851118230221bd1d7a1b2d138189375ed1dcd7d0851118230221bd1d
linuxlinux>= 8186fff7ab649085e2c60d032d9a20a85af1d87c < d4e9a968738bf66d3bb852dd5588d4c7afd6d7f4d4e9a968738bf66d3bb852dd5588d4c7afd6d7f4
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 6.6.18 < 6.6.346.6.34
linuxlinux_kernel>= 6.8 < 6.9.56.9.5

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.