CVE-2024-56629
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Dec 27, 2024
Updated: Jan 15, 2025
CWE ID 476
Summary
CVE-2024-56629 is a vulnerability affecting the Linux kernel that can lead to system crashes due to null pointer dereferences. This issue is caused by certain devices reporting empty product strings, which in turn causes the kernel to dereference a null pointer when accessing dev->product. The issue was identified on an EXCELSIOR DL37-D05 device with a Loongson-LS3A6000-7A2000-DL37 motherboard. The vulnerability was discovered during a kernel panic, as evidenced by the kernel logs provided in the source text.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.