NULL pointer deference in acpi_db_convert_to_package of Linux acpi module
Vulnerability Description
The memory allocation function ACPI_ALLOCATE_ZEROED does not guarantee a successful allocation, but the subsequent code directly dereferences the pointer that receives it, which may lead to null pointer dereference. To fix this issue, a null pointer check should be added. If it is null, return exception code AE_NO_MEMORY.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-24856
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- 白家驹 <baijiaju@buaa.edu.cn>
- 刘怀远 <qq810974084@gmail.com>
More from OpenAnolis
View All →Affected Vendor
OpenAnolis
View all reports →