CVE-2024-57852

Advisory lineage Upstream: 0 Downstream: 5
Analyzed
Published: 27 Feb 2025, 02:18
Last modified:23 May 2026, 15:56

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.01% LOW
0% probability -0.02%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

27 Feb 2025, 02:18
Published
Vulnerability first disclosed
23 May 2026, 15:56
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: smc: Handle missing SCM device Commit ca61d6836e6f ("firmware: qcom: scm: fix a NULL-pointer dereference") makes it explicit that qcom_scm_get_tzmem_pool() can return NULL, therefore its users should handle this.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.01% Percentile: 3%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • linuxlinux

    ≥ ca61d6836e6f4442a77762e1074d2706a2a6e578, < cd955b75849b58b650ca3f87b83bd78cde1da8bc | ≥ ca61d6836e6f4442a77762e1074d2706a2a6e578, < 57a811c0886f3f3677bb4619502b35b5bb917f2e | ≥ ca61d6836e6f4442a77762e1074d2706a2a6e578, < 94f48ecf0a538019ca2025e0b0da391f8e7cc58c | 3d36e2b1d803f0d1cc674115d295a8f20ddb9268 | ≥ 6.11.8, < 6.12 | 6.12

  • linuxlinux_kernel

    ≥ 6.11.8, < 6.12 | ≥ 6.12.1, < 6.12.16 | ≥ 6.13, < 6.13.4 | 6.12 | 6.12:rc7

References (3)