cbcvebase.
CVE-2024-47705
published 2024-10-21

CVE-2024-47705: In the Linux kernel, the following vulnerability has been resolved: block: fix potential invalid pointer dereference in blk_add_partition The…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.2th percentile
In the Linux kernel, the following vulnerability has been resolved: block: fix potential invalid pointer dereference in blk_add_partition The blk_add_partition() function initially used a single if-condition (IS_ERR(part)) to check for errors when adding a partition. This was modified to handle the specific case of -ENXIO separately, allowing the function to proceed without logging the error in this case. However, this change unintentionally left a path where md_autodetect_dev() could be called without confirming that part is a valid pointer. This commit separates the error handling logic by splitting the initial if-condition, improving code readability and handling specific error scenarios explicitly. The function now distinguishes the general error case from -ENXIO without altering the existing behavior of md_autodetect_dev() calls.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= b72053072c0bbe9f1cdfe2ffa3c201c185da2201 < 4bc4272e2506941c3f3d4fb8b0c659ee814dcf6f4bc4272e2506941c3f3d4fb8b0c659ee814dcf6f
linuxlinux>= b72053072c0bbe9f1cdfe2ffa3c201c185da2201 < cc4d21d9492db4e534d3e01253cf885c90dd2a8bcc4d21d9492db4e534d3e01253cf885c90dd2a8b
linuxlinux>= b72053072c0bbe9f1cdfe2ffa3c201c185da2201 < 64cf2a39202ca2d9df5ee70eb310b6141ce2b8ed64cf2a39202ca2d9df5ee70eb310b6141ce2b8ed
linuxlinux>= b72053072c0bbe9f1cdfe2ffa3c201c185da2201 < 80f5bfbb80ea1615290dbc24f49d3d8c86db58fe80f5bfbb80ea1615290dbc24f49d3d8c86db58fe
linuxlinux>= b72053072c0bbe9f1cdfe2ffa3c201c185da2201 < 652039ba477c9a4ab43740cf2cb0d068d53508c2652039ba477c9a4ab43740cf2cb0d068d53508c2
linuxlinux>= b72053072c0bbe9f1cdfe2ffa3c201c185da2201 < afe53ea9b378c376101d99d216f13b6256f75189afe53ea9b378c376101d99d216f13b6256f75189
linuxlinux>= b72053072c0bbe9f1cdfe2ffa3c201c185da2201 < 26e197b7f9240a4ac301dd0ad520c0c697c2ea7d26e197b7f9240a4ac301dd0ad520c0c697c2ea7d
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.2-16.11.2-1
linuxlinux_kernel>= 0 < 6.11.2-16.11.2-1
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137
linuxlinux_kernel>= 0 < 6.8.0-54.566.8.0-54.56
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 5.11 < 5.15.1685.15.168
linuxlinux_kernel>= 5.16 < 6.1.1136.1.113
linuxlinux_kernel>= 5.5 < 5.10.2275.10.227
linuxlinux_kernel>= 6.11 < 6.11.26.11.2
linuxlinux_kernel>= 6.2 < 6.6.546.6.54
linuxlinux_kernel>= 6.7 < 6.10.136.10.13
msrcazl3_kernel_6.6.51.1-5_on_azure_linux_3.0
msrcazl3_kernel_6.6.56.1-5_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.