CVE-2024-47756

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
21/10/2024
Last modified:
03/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> PCI: keystone: Fix if-statement expression in ks_pcie_quirk()<br /> <br /> This code accidentally uses &amp;&amp; where || was intended. It potentially<br /> results in a NULL dereference.<br /> <br /> Thus, fix the if-statement expression to use the correct condition.<br /> <br /> [kwilczynski: commit log]

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.4.284 (including) 5.5 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.1.110 (including) 6.1.113 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.6.51 (including) 6.6.54 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.10.10 (including) 6.10.13 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.11 (including) 6.11.2 (excluding)
cpe:2.3:o:linux:linux_kernel:5.10.226:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15.167:*:*:*:*:*:*:*