Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-43860— remoteproc: imx_rproc: Skip over memory region when node value is NULL

EPSS 0.03% · P9

Affected Version Matrix 18

VendorProductVersion RangeStatus
LinuxLinuxa0ff4aa6f010801b2a61c203c6e09d01b110fddf< 6884fd0283e0831be153fb8d82d9eda8a55acaaaaffected
a0ff4aa6f010801b2a61c203c6e09d01b110fddf< 84beb7738459cac0ff9f8a7c4654b8ff82a702c0affected
a0ff4aa6f010801b2a61c203c6e09d01b110fddf< 6b50462b473fdccdc0dfad73001147e40ff19a66affected
a0ff4aa6f010801b2a61c203c6e09d01b110fddf< 4e13b7c23988c0a13fdca92e94296a3bc2ff9f21affected
a0ff4aa6f010801b2a61c203c6e09d01b110fddf< 9a17cf8b2ce483fa75258bc2cdcf628f24bcf5f8affected
a0ff4aa6f010801b2a61c203c6e09d01b110fddf< 6c9ea3547fad252fe9ae5d3ed7e066e2085bf3a2affected
a0ff4aa6f010801b2a61c203c6e09d01b110fddf< c877a5f5268d4ab8224b9c9fbce3d746e4e72bc9affected
a0ff4aa6f010801b2a61c203c6e09d01b110fddf< 2fa26ca8b786888673689ccc9da6094150939982affected
… +10 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-43860

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
remoteproc: imx_rproc: Skip over memory region when node value is NULL
Source: NVD (National Vulnerability Database)
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: remoteproc: imx_rproc: Skip over memory region when node value is NULL In imx_rproc_addr_init() "nph = of_count_phandle_with_args()" just counts number of phandles. But phandles may be empty. So of_parse_phandle() in the parsing loop (0 < a < nph) may return NULL which is later dereferenced. Adjust this issue by adding NULL-return check. Found by Linux Verification Center (linuxtesting.org) with SVACE. [Fixed title to fit within the prescribed 70-75 charcters]
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于imx_rproc组件在处理内存区域时存在问题,当节点值为空时未能跳过。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux a0ff4aa6f010801b2a61c203c6e09d01b110fddf ~ 6884fd0283e0831be153fb8d82d9eda8a55acaaa -
LinuxLinux 4.14 -

II. Public POCs for CVE-2024-43860

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-43860

登录查看更多情报信息。

Same Patch Batch · Linux · 2024-08-17 · 109 CVEs total

CVE-2024-43819kvm: s390: Reject memory region operations for ucontrol VMs
CVE-2024-43831media: mediatek: vcodec: Handle invalid decoder vsi
CVE-2024-43832s390/uv: Don't call folio_wait_writeback() without a folio reference
CVE-2024-43830leds: trigger: Unregister sysfs attributes before calling deactivate()
CVE-2024-43829drm/qxl: Add check for drm_cvt_mode
CVE-2024-43828ext4: fix infinite loop when replaying fast_commit
CVE-2024-43827drm/amd/display: Add null check before access structs
CVE-2024-43826nfs: pass explicit offset/count to trace events
CVE-2024-43825iio: Fix the sorting functionality in iio_gts_build_avail_time_table
CVE-2024-43823PCI: keystone: Fix NULL pointer dereference in case of DT error in ks_pcie_setup_rc_app_re
CVE-2024-43824PCI: endpoint: pci-epf-test: Make use of cached 'epc_features' in pci_epf_test_core_init()
CVE-2024-43822ASoc: PCM6240: Return directly after a failed devm_kzalloc() in pcmdevice_i2c_probe()
CVE-2024-43821scsi: lpfc: Fix a possible null pointer dereference
CVE-2024-43820dm-raid: Fix WARN_ON_ONCE check for sync_thread in raid_resume
CVE-2024-42317mm/huge_memory: avoid PMD-size page cache if needed
CVE-2024-42320s390/dasd: fix error checks in dasd_copy_pair_store()
CVE-2024-42319mailbox: mtk-cmdq: Move devm_mbox_controller_register() after devm_pm_runtime_enable()
CVE-2024-42318landlock: Don't lose track of restrictions on cred_transfer
CVE-2024-42321net: flow_dissector: use DEBUG_NET_WARN_ON_ONCE
CVE-2024-42316mm/mglru: fix div-by-zero in vmpressure_calc_level()

Showing top 20 of 109 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-43860

No comments yet


Leave a comment