cbcvebase.
CVE-2024-47743
published 2024-10-21

CVE-2024-47743: In the Linux kernel, the following vulnerability has been resolved: KEYS: prevent NULL pointer dereference in find_asymmetric_key() In find_asymmetric_key()…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.8th percentile
In the Linux kernel, the following vulnerability has been resolved: KEYS: prevent NULL pointer dereference in find_asymmetric_key() In find_asymmetric_key(), if all NULLs are passed in the id_{0,1,2} arguments, the kernel will first emit WARN but then have an oops because id_2 gets dereferenced anyway. Add the missing id_2 check and move WARN_ON() to the final else branch to avoid duplicate NULL checks. Found by Linux Verification Center (linuxtesting.org) with Svace static analysis tool.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= 7d30198ee24f2ddcc4fefcd38a9b76bd8ab31360 < 3322fa8f2aa40b0b3651034cd541647a600cc6c03322fa8f2aa40b0b3651034cd541647a600cc6c0
linuxlinux>= 7d30198ee24f2ddcc4fefcd38a9b76bd8ab31360 < a3765b497a4f5224cb2f7a6a2d3357d3066214eea3765b497a4f5224cb2f7a6a2d3357d3066214ee
linuxlinux>= 7d30198ee24f2ddcc4fefcd38a9b76bd8ab31360 < 13b5b401ead95b5d8266f64904086c55b602490013b5b401ead95b5d8266f64904086c55b6024900
linuxlinux>= 7d30198ee24f2ddcc4fefcd38a9b76bd8ab31360 < 0d3b0706ada15c333e6f9faf19590ff715e45d1e0d3b0706ada15c333e6f9faf19590ff715e45d1e
linuxlinux>= 7d30198ee24f2ddcc4fefcd38a9b76bd8ab31360 < 70fd1966c93bf3bfe3fe6d753eb3d83a76597eef70fd1966c93bf3bfe3fe6d753eb3d83a76597eef
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.2-16.11.2-1
linuxlinux_kernel>= 0 < 6.11.2-16.11.2-1
linuxlinux_kernel>= 0 < 6.8.0-54.566.8.0-54.56
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 5.17 < 6.1.1136.1.113
linuxlinux_kernel>= 6.11 < 6.11.26.11.2
linuxlinux_kernel>= 6.2 < 6.6.546.6.54
linuxlinux_kernel>= 6.7 < 6.10.136.10.13
msrcazl3_kernel_6.6.51.1-5_on_azure_linux_3.0
msrcazl3_kernel_6.6.56.1-5_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.