cbcvebase.
CVE-2024-53060
published 2024-11-19

CVE-2024-53060: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: prevent NULL pointer dereference if ATIF is not supported…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.3th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: prevent NULL pointer dereference if ATIF is not supported acpi_evaluate_object() may return AE_NOT_FOUND (failure), which would result in dereferencing buffer.pointer (obj) while being NULL. Although this case may be unrealistic for the current code, it is still better to protect against possible bugs. Bail out also when status is AE_NOT_FOUND. This fixes 1 FORWARD_NULL issue reported by Coverity Report: CID 1600951: Null pointer dereferences (FORWARD_NULL) (cherry picked from commit 91c9e221fe2553edf2db71627d8453f083de87a1)

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
debianlinux-6.1< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
linuxlinux>= 1d7175f9c57b1abf9ecfbdfd53ea760761f52ffe < b9d9881237afeb52eddd70077b7174bf17e2fa30b9d9881237afeb52eddd70077b7174bf17e2fa30
linuxlinux>= 234682910971732cd4da96fd95946e296e486b38 < 2ac7f253deada4d449559b65a1c1cd0a6f6f19b72ac7f253deada4d449559b65a1c1cd0a6f6f19b7
linuxlinux>= 4.19.323 < 4.19.3244.19.324
linuxlinux>= 43b4fa6e0e238c6e2662f4fb61d9f51c2785fb1d < 8d7a28eca7553d35d4ce192fa1f390f2357df41b8d7a28eca7553d35d4ce192fa1f390f2357df41b
linuxlinux>= 5.10.229 < 5.10.2305.10.230
linuxlinux>= 5.15.170 < 5.15.1725.15.172
linuxlinux>= 5.4.285 < 5.4.2865.4.286
linuxlinux>= 58556dcbd5606a5daccaee73b2130bc16b48e025 < ce8a00a00e36f61f5a1e47734332420b68784c43ce8a00a00e36f61f5a1e47734332420b68784c43
linuxlinux>= 6.1.115 < 6.1.1176.1.117
linuxlinux>= 6.11.6 < 6.11.86.11.8
linuxlinux>= 6.6.59 < 6.6.616.6.61
linuxlinux>= 6032287747f874b52dc8b9d7490e2799736e035f < 27fc29b5376998c126c85cf9b15d9dfc2afc9cbe27fc29b5376998c126c85cf9b15d9dfc2afc9cbe
linuxlinux>= 975ede2a7bec52b5da1428829b3439667c8a234b < a613a392417532ca5aaf3deac6e3277aa7aaef2ba613a392417532ca5aaf3deac6e3277aa7aaef2b
linuxlinux>= bf58f03931fdcf7b3c45cb76ac13244477a60f44 < a6dd15981c03f2cdc9a351a278f09b5479d53d2ea6dd15981c03f2cdc9a351a278f09b5479d53d2e
linuxlinux>= cd67af3c1762de4c2483ae4dbdd98f9ea8fa56e3 < 1a9f55ed5b512f510ccd21ad527d532e60550e801a9f55ed5b512f510ccd21ad527d532e60550e80
linuxlinux_kernel< 4.19.3244.19.324
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 4.20 < 5.4.2865.4.286

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.