cbcvebase.
CVE-2024-57852
published 2025-02-27

CVE-2024-57852: In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: smc: Handle missing SCM device Commit ca61d6836e6f ("firmware: qcom…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.8th percentile
In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: smc: Handle missing SCM device Commit ca61d6836e6f ("firmware: qcom: scm: fix a NULL-pointer dereference") makes it explicit that qcom_scm_get_tzmem_pool() can return NULL, therefore its users should handle this.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.16-1 (forky)linux 6.12.16-1 (forky)
linuxlinux
linuxlinux
linuxlinux>= 6.11.8 < 6.126.12
linuxlinux>= ca61d6836e6f4442a77762e1074d2706a2a6e578 < cd955b75849b58b650ca3f87b83bd78cde1da8bccd955b75849b58b650ca3f87b83bd78cde1da8bc
linuxlinux>= ca61d6836e6f4442a77762e1074d2706a2a6e578 < 57a811c0886f3f3677bb4619502b35b5bb917f2e57a811c0886f3f3677bb4619502b35b5bb917f2e
linuxlinux>= ca61d6836e6f4442a77762e1074d2706a2a6e578 < 94f48ecf0a538019ca2025e0b0da391f8e7cc58c94f48ecf0a538019ca2025e0b0da391f8e7cc58c
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.16-16.12.16-1
linuxlinux_kernel>= 0 < 6.12.16-16.12.16-1
linuxlinux_kernel>= 6.11.8 < 6.126.12
linuxlinux_kernel>= 6.12.1 < 6.12.166.12.16
linuxlinux_kernel>= 6.13 < 6.13.46.13.4
msrcazl3_kernel_6.6.96.2-1_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.