CVE-2024-56577

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Dec 27, 2024
Updated: Jan 6, 2025
CWE ID 476

Summary

CVE-2024-56577: A vulnerability has been identified and resolved in the Linux kernel related to the media driver mtk-jpeg. The issue occurs when the workqueue is not destroyed properly in the mtk_jpeg_core.c file, which can lead to a null-pointer dereference. This can result in a kernel panic, as shown in the call trace, with vulnerable code located in destroy_workqueue and mtk_jpegdec_destroy_workqueue functions. The vulnerability can be triggered when the module is being unloaded, potentially causing system instability or crashes.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share