CVE-2024-56782

medium

Description

In the Linux kernel, the following vulnerability has been resolved: ACPI: x86: Add adev NULL check to acpi_quirk_skip_serdev_enumeration() acpi_dev_hid_match() does not check for adev == NULL, dereferencing it unconditional. Add a check for adev being NULL before calling acpi_dev_hid_match(). At the moment acpi_quirk_skip_serdev_enumeration() is never called with a controller_parent without an ACPI companion, but better safe than sorry.

References

https://git.kernel.org/stable/c/e173bce05f7032a8b4964cfef82a4b7668f5f3af

https://git.kernel.org/stable/c/4a49194f587a62d972b602e3e1a2c3cfe6567966

Details

Source: Mitre, NVD

Published: 2025-01-08

Updated: 2025-01-09

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium