CVE-2024-57978

medium

Description

In the Linux kernel, the following vulnerability has been resolved: media: imx-jpeg: Fix potential error pointer dereference in detach_pm() The proble is on the first line: if (jpeg->pd_dev[i] && !pm_runtime_suspended(jpeg->pd_dev[i])) If jpeg->pd_dev[i] is an error pointer, then passing it to pm_runtime_suspended() will lead to an Oops. The other conditions check for both error pointers and NULL, but it would be more clear to use the IS_ERR_OR_NULL() check for that.

References

https://git.kernel.org/stable/c/fde89fe11b44500bfcb2d405825b69a5df805d19

https://git.kernel.org/stable/c/f0b8535a7885ed4fd0b11625addb5476cae0f845

https://git.kernel.org/stable/c/6e601a64f7777e2f78c02db1a8b5ba3b7c5e9e31

https://git.kernel.org/stable/c/1b2af918bb714937a8be6cb637f528585461cd98

https://git.kernel.org/stable/c/1378ffec30367233152b7dbf4fa6a25ee98585d1

Details

Source: Mitre, NVD

Published: 2025-02-27

Updated: 2025-03-07

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium