CVE-2024-57852
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: smc: Handle missing SCM device Commit ca61d6836e6f ("firmware: qcom: scm: fix a NULL-pointer dereference") makes it explicit that qcom_scm_get_tzmem_pool() can return NULL, therefore its users should handle this.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.01%• Percentile: 3%
Techniques & Countermeasures
- CWE-476•NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
Affected Systems
- linux•linux
≥ ca61d6836e6f4442a77762e1074d2706a2a6e578, < cd955b75849b58b650ca3f87b83bd78cde1da8bc | ≥ ca61d6836e6f4442a77762e1074d2706a2a6e578, < 57a811c0886f3f3677bb4619502b35b5bb917f2e | ≥ ca61d6836e6f4442a77762e1074d2706a2a6e578, < 94f48ecf0a538019ca2025e0b0da391f8e7cc58c | 3d36e2b1d803f0d1cc674115d295a8f20ddb9268 | ≥ 6.11.8, < 6.12 | 6.12
- linux•linux_kernel
≥ 6.11.8, < 6.12 | ≥ 6.12.1, < 6.12.16 | ≥ 6.13, < 6.13.4 | 6.12 | 6.12:rc7