cbcvebase.
CVE-2024-41089
published 2024-07-29

CVE-2024-41089: In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_hd_modes In…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.6th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_hd_modes In nv17_tv_get_hd_modes(), the return value of drm_mode_duplicate() is assigned to mode, which will lead to a possible NULL pointer dereference on failure of drm_mode_duplicate(). The same applies to drm_cvt_mode(). Add a check to avoid null pointer dereference.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
debianlinux-6.1< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
linuxlinux
linuxlinux>= 6ee738610f41b59733f63718f0bdbcba7d3a3f12 < ffabad4aa91e33ced3c6ae793fb37771b3e9cb51ffabad4aa91e33ced3c6ae793fb37771b3e9cb51
linuxlinux>= 6ee738610f41b59733f63718f0bdbcba7d3a3f12 < 1c9f2e60150b4f13789064370e37f39e6e060f501c9f2e60150b4f13789064370e37f39e6e060f50
linuxlinux>= 6ee738610f41b59733f63718f0bdbcba7d3a3f12 < 56fc4d3b0bdef691831cd95715a7ca3ebea98b2d56fc4d3b0bdef691831cd95715a7ca3ebea98b2d
linuxlinux>= 6ee738610f41b59733f63718f0bdbcba7d3a3f12 < 5eecb49a6c268dc229005bf6e8167d4001dc09a05eecb49a6c268dc229005bf6e8167d4001dc09a0
linuxlinux>= 6ee738610f41b59733f63718f0bdbcba7d3a3f12 < 30cbf6ffafbbdd8a6e4e5f0a2e9a9827ee83f3ad30cbf6ffafbbdd8a6e4e5f0a2e9a9827ee83f3ad
linuxlinux>= 6ee738610f41b59733f63718f0bdbcba7d3a3f12 < 7ece609b0ce7a7ea8acdf512a77d1fee266216377ece609b0ce7a7ea8acdf512a77d1fee26621637
linuxlinux>= 6ee738610f41b59733f63718f0bdbcba7d3a3f12 < 6e49a157d541e7e97b815a56f4bdfcbc89844a596e49a157d541e7e97b815a56f4bdfcbc89844a59
linuxlinux>= 6ee738610f41b59733f63718f0bdbcba7d3a3f12 < 6d411c8ccc0137a612e0044489030a194ff5c8436d411c8ccc0137a612e0044489030a194ff5c843
linuxlinux_kernel< 4.19.3174.19.317
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.98-16.1.98-1
linuxlinux_kernel>= 0 < 6.9.8-16.9.8-1
linuxlinux_kernel>= 0 < 6.9.8-16.9.8-1
linuxlinux_kernel>= 0 < 5.4.0-195.2155.4.0-195.215
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 0 < 4.4.0-261.2954.4.0-261.295
linuxlinux_kernel>= 0 < 4.15.0-231.2434.15.0-231.243
linuxlinux_kernel>= 4.20 < 5.4.2795.4.279
linuxlinux_kernel>= 5.11 < 5.15.1625.15.162
linuxlinux_kernel>= 5.16 < 6.1.976.1.97
linuxlinux_kernel>= 5.5 < 5.10.2215.10.221

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.