Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-56629— HID: wacom: fix when get product name maybe null pointer

AI Predicted 5.3 Difficulty: Hard EPSS 0.21% · P12

Possible ATT&CK Techniques 1AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 16

VendorProductVersion RangeStatus
LinuxLinux09dc28acaec74d7467c7c9b81dc8676e5bc957ce< d031eef3cc2e3bf524509e38fb898e5335c85c96affected
09dc28acaec74d7467c7c9b81dc8676e5bc957ce< 5912a921289edb34d40aeab32ea6d52d41e75fedaffected
09dc28acaec74d7467c7c9b81dc8676e5bc957ce< 2ed3e3a3ac06af8a6391c3d6a7791b7967d7d43aaffected
09dc28acaec74d7467c7c9b81dc8676e5bc957ce< 2cd323c55bd3f356bf23ae1b4c20100abcdc29d6affected
09dc28acaec74d7467c7c9b81dc8676e5bc957ce< a7f0509556fa2f9789639dbcee9eed46e471ccefaffected
09dc28acaec74d7467c7c9b81dc8676e5bc957ce< e689bc6697a7fcebd4a945ab0b1e1112c76024d8affected
09dc28acaec74d7467c7c9b81dc8676e5bc957ce< 59548215b76be98cf3422eea9a67d6ea578aca3daffected
4.14affected
… +8 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-56629

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
HID: wacom: fix when get product name maybe null pointer
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: HID: wacom: fix when get product name maybe null pointer Due to incorrect dev->product reporting by certain devices, null pointer dereferences occur when dev->product is empty, leading to potential system crashes. This issue was found on EXCELSIOR DL37-D05 device with Loongson-LS3A6000-7A2000-DL37 motherboard. Kernel logs: [ 56.470885] usb 4-3: new full-speed USB device number 4 using ohci-pci [ 56.671638] usb 4-3: string descriptor 0 read error: -22 [ 56.671644] usb 4-3: New USB device found, idVendor=056a, idProduct=0374, bcdDevice= 1.07 [ 56.671647] usb 4-3: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 56.678839] hid-generic 0003:056A:0374.0004: hiddev0,hidraw3: USB HID v1.10 Device [HID 056a:0374] on usb-0000:00:05.0-3/input0 [ 56.697719] CPU 2 Unable to handle kernel paging request at virtual address 0000000000000000, era == 90000000066e35c8, ra == ffff800004f98a80 [ 56.697732] Oops[#1]: [ 56.697734] CPU: 2 PID: 2742 Comm: (udev-worker) Tainted: G OE 6.6.0-loong64-desktop #25.00.2000.015 [ 56.697737] Hardware name: Inspur CE520L2/C09901N000000000, BIOS 2.09.00 10/11/2024 [ 56.697739] pc 90000000066e35c8 ra ffff800004f98a80 tp 9000000125478000 sp 900000012547b8a0 [ 56.697741] a0 0000000000000000 a1 ffff800004818b28 a2 0000000000000000 a3 0000000000000000 [ 56.697743] a4 900000012547b8f0 a5 0000000000000000 a6 0000000000000000 a7 0000000000000000 [ 56.697745] t0 ffff800004818b2d t1 0000000000000000 t2 0000000000000003 t3 0000000000000005 [ 56.697747] t4 0000000000000000 t5 0000000000000000 t6 0000000000000000 t7 0000000000000000 [ 56.697748] t8 0000000000000000 u0 0000000000000000 s9 0000000000000000 s0 900000011aa48028 [ 56.697750] s1 0000000000000000 s2 0000000000000000 s3 ffff800004818e80 s4 ffff800004810000 [ 56.697751] s5 90000001000b98d0 s6 ffff800004811f88 s7 ffff800005470440 s8 0000000000000000 [ 56.697753] ra: ffff800004f98a80 wacom_update_name+0xe0/0x300 [wacom] [ 56.697802] ERA: 90000000066e35c8 strstr+0x28/0x120 [ 56.697806] CRMD: 000000b0 (PLV0 -IE -DA +PG DACF=CC DACM=CC -WE) [ 56.697816] PRMD: 0000000c (PPLV0 +PIE +PWE) [ 56.697821] EUEN: 00000000 (-FPE -SXE -ASXE -BTE) [ 56.697827] ECFG: 00071c1d (LIE=0,2-4,10-12 VS=7) [ 56.697831] ESTAT: 00010000 [PIL] (IS= ECode=1 EsubCode=0) [ 56.697835] BADV: 0000000000000000 [ 56.697836] PRID: 0014d000 (Loongson-64bit, Loongson-3A6000) [ 56.697838] Modules linked in: wacom(+) bnep bluetooth rfkill qrtr nls_iso8859_1 nls_cp437 snd_hda_codec_conexant snd_hda_codec_generic ledtrig_audio snd_hda_codec_hdmi snd_hda_intel snd_intel_dspcfg snd_hda_codec snd_hda_core snd_hwdep snd_pcm snd_timer snd soundcore input_leds mousedev led_class joydev deepin_netmonitor(OE) fuse nfnetlink dmi_sysfs ip_tables x_tables overlay amdgpu amdxcp drm_exec gpu_sched drm_buddy radeon drm_suballoc_helper i2c_algo_bit drm_ttm_helper r8169 ttm drm_display_helper spi_loongson_pci xhci_pci cec xhci_pci_renesas spi_loongson_core hid_generic realtek gpio_loongson_64bit [ 56.697887] Process (udev-worker) (pid: 2742, threadinfo=00000000aee0d8b4, task=00000000a9eff1f3) [ 56.697890] Stack : 0000000000000000 ffff800004817e00 0000000000000000 0000251c00000000 [ 56.697896] 0000000000000000 00000011fffffffd 0000000000000000 0000000000000000 [ 56.697901] 0000000000000000 1b67a968695184b9 0000000000000000 90000001000b98d0 [ 56.697906] 90000001000bb8d0 900000011aa48028 0000000000000000 ffff800004f9d74c [ 56.697911] 90000001000ba000 ffff800004f9ce58 0000000000000000 ffff800005470440 [ 56.697916] ffff800004811f88 90000001000b98d0 9000000100da2aa8 90000001000bb8d0 [ 56.697921] 0000000000000000 90000001000ba000 900000011aa48028 ffff800004f9d74c [ 56.697926] ffff8000054704e8 90000001000bb8b8 90000001000ba000 0000000000000000 [ 56.697931] 90000001000bb8d0 ---truncated---
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于f2fs模块中f2fs_submit_page_bio函数中的空指针取消引用,导致内核崩溃。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 09dc28acaec74d7467c7c9b81dc8676e5bc957ce ~ d031eef3cc2e3bf524509e38fb898e5335c85c96 -
LinuxLinux 4.14 -

II. Public POCs for CVE-2024-56629

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-56629

登录查看更多情报信息。

Patches & Fixes for CVE-2024-56629 (7)

Same Patch Batch · Linux · 2024-12-27 · 221 CVEs total

CVE-2024-566409.8 CRITICALnet/smc: fix LGR and link use-after-free issue
CVE-2024-566459.8 CRITICALcan: j1939: j1939_session_new(): fix skb reference counting
CVE-2024-531699.8 CRITICALnvme-fabrics: fix kernel crash while shutting down controller
CVE-2024-532099.8 CRITICALbnxt_en: Fix receive ring space parameters when XDP is active
CVE-2024-532069.8 CRITICALtcp: Fix use-after-free of nreq in reqsk_timer_handler().
CVE-2024-566569.8 CRITICALbnxt_en: Fix aggregation ID mask to prevent oops on 5760X chips
CVE-2024-531869.8 CRITICALksmbd: fix use-after-free in SMB request handling
CVE-2024-531769.8 CRITICALsmb: During unmount, ensure all cached dir instances drop their dentry
CVE-2024-531779.8 CRITICALsmb: prevent use-after-free due to open_cached_dir error paths
CVE-2024-531799.8 CRITICALsmb: client: fix use-after-free of signing key
CVE-2024-565918.8 HIGHBluetooth: hci_conn: Use disable_delayed_work_sync
CVE-2024-566268.8 HIGHksmbd: fix Out-of-Bounds Write in ksmbd_vfs_stream_write
CVE-2024-532378.8 HIGHBluetooth: fix use-after-free in device_for_each_child()
CVE-2024-532248.8 HIGHRDMA/mlx5: Move events notifier registration to be after device registration
CVE-2024-566518.8 HIGHcan: hi311x: hi3110_can_ist(): fix potential use-after-free
CVE-2024-566538.8 HIGHBluetooth: btmtk: avoid UAF in btmtk_process_coredump
CVE-2024-566698.8 HIGHiommu/vt-d: Remove cache tags before disabling ATS
CVE-2024-566278.1 HIGHksmbd: fix Out-of-Bounds Read in ksmbd_vfs_stream_read
CVE-2024-566067.8 HIGHaf_packet: avoid erroring out after sock_init_data() in packet_create()
CVE-2024-532397.8 HIGHALSA: 6fire: Release resources at card release

Showing top 20 of 221 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-56629

No comments yet


Leave a comment