SB20241230126 - NULL pointer dereference in Linux kernel radio wl128x driver
Published: December 30, 2024 Updated: May 11, 2025
Security Bulletin ID
SB20241230126
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2024-56700)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the fmc_send_cmd() function in drivers/media/radio/wl128x/fmdrv_common.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2e63c908de357048180516b84740ed62dac0b269
- https://git.kernel.org/stable/c/372dc9509122e5d45d4c12978e31c3c7d00aaca4
- https://git.kernel.org/stable/c/378ce4e08ca2b1ac7bbf1d57b68643ca4226c5f8
- https://git.kernel.org/stable/c/3c818ad07e964bca3d27adac1e1f50e1e3c9180e
- https://git.kernel.org/stable/c/80a3b2ee01eecf22dfa06968b3cde92c691dea10
- https://git.kernel.org/stable/c/ca59f9956d4519ab18ab2270be47c6b8c6ced091
- https://git.kernel.org/stable/c/d16109c9fdc1b8cea4fe63b42e06e926c3f68990
- https://git.kernel.org/stable/c/d7408a052aa1b4f6fb6f1c7a8877b84017a07ac9
- https://git.kernel.org/stable/c/ed228b74d8a500380150965d5becabf9a1e33141
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.174