CVE-2024-50058
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
21/10/2024
Last modified:
12/05/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
serial: protect uart_port_dtr_rts() in uart_shutdown() too<br />
<br />
Commit af224ca2df29 (serial: core: Prevent unsafe uart port access, part<br />
3) added few uport == NULL checks. It added one to uart_shutdown(), so<br />
the commit assumes, uport can be NULL in there. But right after that<br />
protection, there is an unprotected "uart_port_dtr_rts(uport, false);"<br />
call. That is invoked only if HUPCL is set, so I assume that is the<br />
reason why we do not see lots of these reports.<br />
<br />
Or it cannot be NULL at this point at all for some reason :P.<br />
<br />
Until the above is investigated, stay on the safe side and move this<br />
dereference to the if too.<br />
<br />
I got this inconsistency from Coverity under CID 1585130. Thanks.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.6.57 (excluding) | |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.11.4 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/2fe399bb8efd0d325ab1138cf8e3ecf23a39e96d
- https://git.kernel.org/stable/c/399927f0f875b93f3d5a0336d382ba48b8671eb2
- https://git.kernel.org/stable/c/602babaa84d627923713acaf5f7e9a4369e77473
- https://git.kernel.org/stable/c/76ed24a34223bb2c6b6162e1d8389ec4e602a290
- https://git.kernel.org/stable/c/d7b5876a6e74cdf8468a478be6b23f2f5464ac7a
- https://git.kernel.org/stable/c/e418d91195d29d5f9c9685ff309b92b04b41dc40
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
- https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html
- https://cert-portal.siemens.com/productcert/html/ssa-265688.html



