cbcvebase.
CVE-2024-45002
published 2024-09-04

CVE-2024-45002: In the Linux kernel, the following vulnerability has been resolved: rtla/osnoise: Prevent NULL dereference in error handling If the "tool->data" allocation…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.1th percentile
In the Linux kernel, the following vulnerability has been resolved: rtla/osnoise: Prevent NULL dereference in error handling If the "tool->data" allocation fails then there is no need to call osnoise_free_top() and, in fact, doing so will lead to a NULL dereference.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= 1eceb2fc2ca549a170d7ee7cd1fde2daeda646ac < fc575212c6b75d538e1a0a74f4c7e2ac73bc46acfc575212c6b75d538e1a0a74f4c7e2ac73bc46ac
linuxlinux>= 1eceb2fc2ca549a170d7ee7cd1fde2daeda646ac < 753f1745146e03abd17eec8eee95faffc96d743d753f1745146e03abd17eec8eee95faffc96d743d
linuxlinux>= 1eceb2fc2ca549a170d7ee7cd1fde2daeda646ac < abdb9ddaaab476e62805e36cce7b4ef8413ffd01abdb9ddaaab476e62805e36cce7b4ef8413ffd01
linuxlinux>= 1eceb2fc2ca549a170d7ee7cd1fde2daeda646ac < 90574d2a675947858b47008df8d07f75ea50d0d090574d2a675947858b47008df8d07f75ea50d0d0
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.7-16.10.7-1
linuxlinux_kernel>= 0 < 6.10.7-16.10.7-1
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 5.17 < 6.1.1076.1.107
linuxlinux_kernel>= 6.2 < 6.6.486.6.48
linuxlinux_kernel>= 6.7 < 6.10.76.10.7
msrcazl3_kernel_6.6.47.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.51.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.