CVE-2024-50240
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Nov 9, 2024
Updated: Nov 14, 2024
CWE ID 476
Summary
CVE-2024-50240 is a Linux kernel vulnerability that stems from the phy: qcom: qmp-usb driver. The issue arises due to the removal of driver data initialization during probe, which was inadvertently overlooked when most other users of the platform device driver data were eliminated in commit 413db06c05e7. This oversight resulted in a NULL-pointer dereference upon runtime suspend. However, it is noteworthy that runtime PM, which is currently required for this driver to exhibit the vulnerability, is not widely used and must be manually enabled through sysfs.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX