CVE-2024-56620
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Dec 27, 2024
Updated: Jan 8, 2025
CWE ID 476
Summary
CVE-2024-56620 is a newly discovered kernel vulnerability in Linux that affects the SCSI subsystem, specifically the ufs driver for Qualcomm platforms. If ESI is not enabled, freeing MSIs will result in a NULL pointer dereference, leading to a kernel panic with the message "Unable to handle kernel NULL pointer dereference at virtual address 0000000000000008". This issue can potentially be exploited by attackers to gain unauthorized access or cause system instability. The vulnerability has been resolved in recent Linux kernel updates.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX