CVE-2024-53060NULL Pointer Dereference in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 95.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 19
Latest updateAug 14

Description

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: prevent NULL pointer dereference if ATIF is not supported acpi_evaluate_object() may return AE_NOT_FOUND (failure), which would result in dereferencing buffer.pointer (obj) while being NULL. Although this case may be unrealistic for the current code, it is still better to protect against possible bugs. Bail out also when status is AE_NOT_FOUND. This fixes 1 FORWARD_NULL issue reported by Coverity Report: CID 160

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages12 packages

Patches

🔴Vulnerability Details

8
OSV
linux-hwe-6.8 vulnerabilities2025-04-24
OSV
linux, linux-aws, linux-azure, linux-azure-6.8, linux-ibm, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-oem-6.8, linux-oracle, linux-oracl2025-04-23
OSV
linux-realtime vulnerabilities2025-04-23
OSV
linux-gcp-6.8 vulnerabilities2025-04-23
OSV
linux-aws-6.8 vulnerabilities2025-04-23

📋Vendor Advisories

10
CISA ICS
Siemens Third-Party Components in SINEC OS2025-08-14
Ubuntu
Linux kernel (HWE) vulnerabilities2025-04-24
Ubuntu
Linux kernel (Real-time) vulnerabilities2025-04-23
Ubuntu
Linux kernel vulnerabilities2025-04-23
Ubuntu
Linux kernel vulnerabilities2025-04-23
CVE-2024-53060 — NULL Pointer Dereference in Linux | cvebase