PT-2024-33892 · Linux+5 · Linux Kernel+5
Published
2024-10-21
·
Updated
2026-05-26
·
CVE-2024-50056
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
The issue concerns a potential dereferencing of ERR PTR() in the Linux kernel, specifically in the uvc v4l2.c file. This affects the find format by pix() and uvc v4l2 enum format() functions, as well as a similar issue in the uvc v4l2 try format() function. The problem is related to smatch errors, including drivers/usb/gadget/function/uvc v4l2.c:124 find format by pix() and drivers/usb/gadget/function/uvc v4l2.c:392 uvc v4l2 enum format(), where 'fmtdesc' dereferencing possible ERR PTR() is reported.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu