Wind River Support Network

HomeDefectsLIN1024-2781
Fixed

LIN1024-2781 : Security Advisory - linux - CVE-2024-40982

Created: Jul 13, 2024    Updated: Sep 10, 2024
Resolved Date: Jul 14, 2024
Found In Version: 10.24.33.1
Fix Version: 10.24.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

ssb: Fix potential NULL pointer dereference in ssb_device_uevent()

The ssb_device_uevent() function first attempts to convert the 'dev' pointer
to 'struct ssb_device *'. However, it mistakenly dereferences 'dev' before
performing the NULL check, potentially leading to a NULL pointer
dereference if 'dev' is NULL.

To fix this issue, move the NULL check before dereferencing the 'dev' pointer,
ensuring that the pointer is valid before attempting to use it.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

CREATE(Triage):(User=admin) CVE-2024-40982 (https://nvd.nist.gov/vuln/detail/CVE-2024-40982)

CVEs


Live chat
Online