CVE-2024-27025
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: nbd: null check for nla_nest_start nla_nest_start() may fail and return NULL. Insert a check and set errno based on other call sites within the same source code.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.01%• Percentile: 1%
Techniques & Countermeasures
- CWE-476•NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
Affected Systems
- debian•debian_linux
10.0
- linux•linux
≥ 47d902b90a32a42a3d33aef3a02170fc6f70aa23, < 44214d744be32a4769faebba764510888f1eb19e | ≥ 47d902b90a32a42a3d33aef3a02170fc6f70aa23, < 4af837db0fd3679fabc7b7758397090b0c06dced | ≥ 47d902b90a32a42a3d33aef3a02170fc6f70aa23, < 98e60b538e66c90b9a856828c71d4e975ebfa797 | ≥ 47d902b90a32a42a3d33aef3a02170fc6f70aa23, < 96436365e5d80d0106ea785a4f80a58e7c9edff8 | ≥ 47d902b90a32a42a3d33aef3a02170fc6f70aa23, < b7f5aed55829f376e4f7e5ea5b80ccdcb023e983 | ≥ 47d902b90a32a42a3d33aef3a02170fc6f70aa23, < e803040b368d046434fbc8a91945c690332c4fcf | ≥ 47d902b90a32a42a3d33aef3a02170fc6f70aa23, < ba6a9970ce9e284cbc04099361c58731e308596a | ≥ 47d902b90a32a42a3d33aef3a02170fc6f70aa23, < 31edf4bbe0ba27fd03ac7d87eb2ee3d2a231af6d | 4.12
- linux•linux_kernel
≥ 4.12, < 5.4.273 | ≥ 5.5, < 5.10.214 | ≥ 5.11, < 5.15.153 | ≥ 5.16, < 6.1.83 | ≥ 6.2, < 6.6.23 | ≥ 6.7, < 6.7.11 | ≥ 6.8, < 6.8.2
References (10)
- https://git.kernel.org/stable/c/44214d744be32a4769faebba764510888f1eb19e
- https://git.kernel.org/stable/c/4af837db0fd3679fabc7b7758397090b0c06dced
- https://git.kernel.org/stable/c/98e60b538e66c90b9a856828c71d4e975ebfa797
- https://git.kernel.org/stable/c/96436365e5d80d0106ea785a4f80a58e7c9edff8
- https://git.kernel.org/stable/c/b7f5aed55829f376e4f7e5ea5b80ccdcb023e983
- https://git.kernel.org/stable/c/e803040b368d046434fbc8a91945c690332c4fcf
- https://git.kernel.org/stable/c/ba6a9970ce9e284cbc04099361c58731e308596a
- https://git.kernel.org/stable/c/31edf4bbe0ba27fd03ac7d87eb2ee3d2a231af6d
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html
- https://cert-portal.siemens.com/productcert/html/ssa-265688.html