cbcvebase.
CVE-2024-45028
published 2024-09-11

CVE-2024-45028: In the Linux kernel, the following vulnerability has been resolved: mmc: mmc_test: Fix NULL dereference on allocation failure If the "test->highmem =…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.2th percentile
In the Linux kernel, the following vulnerability has been resolved: mmc: mmc_test: Fix NULL dereference on allocation failure If the "test->highmem = alloc_pages()" allocation fails then calling __free_pages(test->highmem) will result in a NULL dereference. Also change the error code to -ENOMEM instead of returning success.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= 2661081f5ab9cb25359d27f88707a018cf4e68e9 < e97be13a9f51284da450dd2a592e3fa87b49cdc9e97be13a9f51284da450dd2a592e3fa87b49cdc9
linuxlinux>= 2661081f5ab9cb25359d27f88707a018cf4e68e9 < 2b507b03991f44dfb202fc2a82c9874d1b1f0c062b507b03991f44dfb202fc2a82c9874d1b1f0c06
linuxlinux>= 2661081f5ab9cb25359d27f88707a018cf4e68e9 < 9b9ba386d7bfdbc38445932c90fa9444c0524bea9b9ba386d7bfdbc38445932c90fa9444c0524bea
linuxlinux>= 2661081f5ab9cb25359d27f88707a018cf4e68e9 < e40515582141a9e7c84b269be699c05236a499a6e40515582141a9e7c84b269be699c05236a499a6
linuxlinux>= 2661081f5ab9cb25359d27f88707a018cf4e68e9 < 3b4e76ceae5b5a46c968bd952f551ce173809f633b4e76ceae5b5a46c968bd952f551ce173809f63
linuxlinux>= 2661081f5ab9cb25359d27f88707a018cf4e68e9 < cac2815f49d343b2f0acc4973d2c14918ac3ab0ccac2815f49d343b2f0acc4973d2c14918ac3ab0c
linuxlinux>= 2661081f5ab9cb25359d27f88707a018cf4e68e9 < ecb15b8ca12c0cbdab81e307e9795214d8b90890ecb15b8ca12c0cbdab81e307e9795214d8b90890
linuxlinux>= 2661081f5ab9cb25359d27f88707a018cf4e68e9 < a1e627af32ed60713941cbfc8075d44cad07f6dda1e627af32ed60713941cbfc8075d44cad07f6dd
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.7-16.10.7-1
linuxlinux_kernel>= 0 < 6.10.7-16.10.7-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 2.6.27 < 4.19.3214.19.321
linuxlinux_kernel>= 4.20 < 5.4.2835.4.283
linuxlinux_kernel>= 5.11 < 5.15.1665.15.166
linuxlinux_kernel>= 5.16 < 6.1.1076.1.107
linuxlinux_kernel>= 5.5 < 5.10.2255.10.225
linuxlinux_kernel>= 6.2 < 6.6.486.6.48

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.