cbcvebase.
CVE-2024-46822
published 2024-09-27

CVE-2024-46822: In the Linux kernel, the following vulnerability has been resolved: arm64: acpi: Harden get_cpu_for_acpi_id() against missing CPU entry In a review discussion…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.6th percentile
In the Linux kernel, the following vulnerability has been resolved: arm64: acpi: Harden get_cpu_for_acpi_id() against missing CPU entry In a review discussion of the changes to support vCPU hotplug where a check was added on the GICC being enabled if was online, it was noted that there is need to map back to the cpu and use that to index into a cpumask. As such, a valid ID is needed. If an MPIDR check fails in acpi_map_gic_cpu_interface() it is possible for the entry in cpu_madt_gicc[cpu] == NULL. This function would then cause a NULL pointer dereference. Whilst a path to trigger this has not been established, harden this caller against the possibility.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= 0be7320a635c2e434e8b67e0e9474a85ceb421c4 < f57769ff6fa7f97f1296965f20e8a2bb3ee9fd0ff57769ff6fa7f97f1296965f20e8a2bb3ee9fd0f
linuxlinux>= 0be7320a635c2e434e8b67e0e9474a85ceb421c4 < 4c3b21204abb4fa3ab310fbbb5cf7f0e85f3a1bc4c3b21204abb4fa3ab310fbbb5cf7f0e85f3a1bc
linuxlinux>= 0be7320a635c2e434e8b67e0e9474a85ceb421c4 < 945be49f4e832a9184c313fdf8917475438a795b945be49f4e832a9184c313fdf8917475438a795b
linuxlinux>= 0be7320a635c2e434e8b67e0e9474a85ceb421c4 < 40cae0df42e5e7f7a1c0f32deed9c4027c1ba94e40cae0df42e5e7f7a1c0f32deed9c4027c1ba94e
linuxlinux>= 0be7320a635c2e434e8b67e0e9474a85ceb421c4 < 62ca6d3a905b4c40cd942f3cc645a6718f8bc7e762ca6d3a905b4c40cd942f3cc645a6718f8bc7e7
linuxlinux>= 0be7320a635c2e434e8b67e0e9474a85ceb421c4 < bc7fbb37e3d2df59336eadbd6a56be632e3c7df7bc7fbb37e3d2df59336eadbd6a56be632e3c7df7
linuxlinux>= 0be7320a635c2e434e8b67e0e9474a85ceb421c4 < 2488444274c70038eb6b686cba5f1ce48ebb9cdd2488444274c70038eb6b686cba5f1ce48ebb9cdd
linuxlinux_kernel< 5.4.2845.4.284
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 5.11 < 5.15.1675.15.167
linuxlinux_kernel>= 5.16 < 6.1.1106.1.110
linuxlinux_kernel>= 5.5 < 5.10.2265.10.226
linuxlinux_kernel>= 6.2 < 6.6.516.6.51
linuxlinux_kernel>= 6.7 < 6.10.106.10.10
msrcazl3_kernel_6.6.47.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.51.1-5_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.