VYPR
Medium severity5.5NVD Advisory· Published Jun 25, 2024· Updated Jun 17, 2026

CVE-2024-39470

CVE-2024-39470

Description

In the Linux kernel, the following vulnerability has been resolved:

eventfs: Fix a possible null pointer dereference in eventfs_find_events()

In function eventfs_find_events,there is a potential null pointer that may be caused by calling update_events_attr which will perform some operations on the members of the ei struct when ei is NULL.

Hence,When ei->is_freed is set,return NULL directly.

Affected products

4
  • Linux/Kernel3 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=6.6.18,<6.6.34
    • (no CPE)
    • (no CPE)range: 6.8
  • osv-coords
    Range: < 6.6.34

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.