#VU94966 NULL pointer dereference in Linux kernel - CVE-2024-41095


Vulnerability identifier: #VU94966

Vulnerability risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-41095

CWE-ID: CWE-476

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the nv17_tv_get_ld_modes() function in drivers/gpu/drm/nouveau/dispnv04/tvnv17.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions


External links
https://git.kernel.org/stable/c/9289cd3450d1da3e271ef4b054d4d2932c41243e
https://git.kernel.org/stable/c/dbd75f32252508ed6c46c3288a282c301a57ceeb
https://git.kernel.org/stable/c/259549b2ccf795b7f91f7b5aba47286addcfa389
https://git.kernel.org/stable/c/0d17604f2e44b3df21e218fe8fb3b836d41bac49
https://git.kernel.org/stable/c/f95ed0f54b3d3faecae1140ddab854f904a6e7c8
https://git.kernel.org/stable/c/cb751e48bbcffd292090f7882b23b215111b3d72
https://git.kernel.org/stable/c/bdda5072494f2a7215d94fc4124ad1949a218714
https://git.kernel.org/stable/c/66edf3fb331b6c55439b10f9862987b0916b3726


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability