Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-39464— media: v4l: async: Fix notifier list entry init

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于空指针取消引用。

AI Predicted 4.4 Difficulty: Trivial EPSS 0.21% · P12

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 8

VendorProduct Version RangeStatus
Linux Linux b8ec754ae4c563f6aab8c0cb47aeb2eae67f1da3< a80d1da923f671c1e6a14e8417cd2f117b27a442 affected
b8ec754ae4c563f6aab8c0cb47aeb2eae67f1da3< 44f6d619c30f0c65fcdd2b6eba70fdb4460d87ad affected
b8ec754ae4c563f6aab8c0cb47aeb2eae67f1da3< 6d8acd02c4c6a8f917eefac1de2e035521ca119d affected
6.6 affected
< 6.6 unaffected
6.6.34≤ 6.6.* unaffected
6.9.5≤ 6.9.* unaffected
6.10≤ * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-39464

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
media: v4l: async: Fix notifier list entry init
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: media: v4l: async: Fix notifier list entry init struct v4l2_async_notifier has several list_head members, but only waiting_list and done_list are initialized. notifier_entry was kept 'zeroed' leading to an uninitialized list_head. This results in a NULL-pointer dereference if csi2_async_register() fails, e.g. node for remote endpoint is disabled, and returns -ENOTCONN. The following calls to v4l2_async_nf_unregister() results in a NULL pointer dereference. Add the missing list head initializer.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于空指针取消引用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux b8ec754ae4c563f6aab8c0cb47aeb2eae67f1da3 ~ a80d1da923f671c1e6a14e8417cd2f117b27a442 -
Linux Linux 6.6 -

II. Public POCs for CVE-2024-39464

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-39464

登录查看更多情报信息。

Other References for CVE-2024-39464 (2)

Same Patch Batch · Linux · 2024-06-25 · 24 CVEs total

CVE-2024-39293 9.8 CRITICAL Revert "xsk: Support redirect to any socket bound to the same umem"
CVE-2024-39471 7.8 HIGH drm/amdgpu: add error handle to avoid out-of-bounds
CVE-2024-37354 7.8 HIGH btrfs: fix crash on racing fsync and size-extending write into prealloc
CVE-2024-37078 7.8 HIGH nilfs2: fix potential kernel bug due to lack of writeback flag waiting
CVE-2024-38306 7.8 HIGH btrfs: protect folio::private when attaching extent buffer folios
CVE-2024-38385 7.8 HIGH genirq/irqdesc: Prevent use-after-free in irq_find_at_or_after()
CVE-2024-39467 7.8 HIGH f2fs: fix to do sanity check on i_xattr_nid in sanity_check_inode()
CVE-2024-39463 7.8 HIGH 9p: add missing locking around taking dentry fid list
CVE-2024-39468 7.5 HIGH smb: client: fix deadlock in smb2_find_smb_tcon()
CVE-2024-39469 7.1 HIGH nilfs2: fix nilfs_empty_dir() misjudgment and long loop on I/O errors
CVE-2024-39301 net/9p: fix uninit-value in p9_client_rpc()
CVE-2024-39470 eventfs: Fix a possible null pointer dereference in eventfs_find_events()
CVE-2024-39466 thermal/drivers/qcom/lmh: Check for SCM availability at probe
CVE-2024-39465 media: mgb4: Fix double debugfs remove
CVE-2024-39462 clk: bcm: dvp: Assign ->num before accessing ->hws
CVE-2024-39461 clk: bcm: rpi: Assign ->num before accessing ->hws
CVE-2024-39371 io_uring: check for non-NULL file pointer in io_file_can_poll()
CVE-2021-4440 x86/xen: Drop USERGS_SYSRET64 paravirt call
CVE-2024-39298 mm/memory-failure: fix handling of dissolved but not taken off from buddy pages
CVE-2024-39296 bonding: fix oops during rmmod

Showing top 20 of 24 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-39464

No comments yet


Leave a comment