cbcvebase.
CVE-2024-46685
published 2024-09-13

CVE-2024-46685: In the Linux kernel, the following vulnerability has been resolved: pinctrl: single: fix potential NULL dereference in pcs_get_function()…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.5th percentile
In the Linux kernel, the following vulnerability has been resolved: pinctrl: single: fix potential NULL dereference in pcs_get_function() pinmux_generic_get_function() can return NULL and the pointer 'function' was dereferenced without checking against NULL. Add checking of pointer 'function' in pcs_get_function(). Found by code review.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= 571aec4df5b72a80f80d1e524da8fbd7ff525c98 < 0a2bab5ed161318f57134716accba0a30f3af1910a2bab5ed161318f57134716accba0a30f3af191
linuxlinux>= 571aec4df5b72a80f80d1e524da8fbd7ff525c98 < 2cea369a5c2e85ab14ae716da1d1cc6d25c85e112cea369a5c2e85ab14ae716da1d1cc6d25c85e11
linuxlinux>= 571aec4df5b72a80f80d1e524da8fbd7ff525c98 < 4e9436375fcc9bd2a60ee96aba6ed53f7a377d104e9436375fcc9bd2a60ee96aba6ed53f7a377d10
linuxlinux>= 571aec4df5b72a80f80d1e524da8fbd7ff525c98 < 6341c2856785dca7006820b127278058a180c0756341c2856785dca7006820b127278058a180c075
linuxlinux>= 571aec4df5b72a80f80d1e524da8fbd7ff525c98 < 8f0bd526921b6867c2f10a83cd4fd14139adcd928f0bd526921b6867c2f10a83cd4fd14139adcd92
linuxlinux>= 571aec4df5b72a80f80d1e524da8fbd7ff525c98 < 4ed45fe99ec9e3c9478bd634624cd05a57d002f74ed45fe99ec9e3c9478bd634624cd05a57d002f7
linuxlinux>= 571aec4df5b72a80f80d1e524da8fbd7ff525c98 < 292151af6add3e5ab11b2e9916cffa5f52859a1f292151af6add3e5ab11b2e9916cffa5f52859a1f
linuxlinux>= 571aec4df5b72a80f80d1e524da8fbd7ff525c98 < 1c38a62f15e595346a1106025722869e87ffe0441c38a62f15e595346a1106025722869e87ffe044
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.9-16.10.9-1
linuxlinux_kernel>= 0 < 6.10.9-16.10.9-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 4.11 < 4.19.3214.19.321
linuxlinux_kernel>= 4.20 < 5.4.2835.4.283
linuxlinux_kernel>= 5.11 < 5.15.1665.15.166
linuxlinux_kernel>= 5.16 < 6.1.1086.1.108
linuxlinux_kernel>= 5.5 < 5.10.2255.10.225
linuxlinux_kernel>= 6.2 < 6.6.496.6.49

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.