Vulnerability identifier: #VU96349
Vulnerability risk: Low
CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID:
CWE-ID:
CWE-476
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Linux kernel
Operating systems & Components /
Operating system
Vendor: Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the gsmi_get_variable() function in drivers/firmware/google/gsmi.c. A local user can perform a denial of service (DoS) attack.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Linux kernel:
External links
http://git.kernel.org/stable/c/ee5763ef829bd923033510de6d1df7c73f085e4b
http://git.kernel.org/stable/c/32313c11bdc8a02c577abaf865be3664ab30410a
http://git.kernel.org/stable/c/ffef77794fb5f1245c3249b86342bad2299accb5
http://git.kernel.org/stable/c/ae2a9dcc8caa60b1e14671294e5ec902ea5d1dfd
http://git.kernel.org/stable/c/eb0421d90f916dffe96b4c049ddf01c0c50620d2
http://git.kernel.org/stable/c/6646d769fdb0ce4318ef9afd127f8526d1ca8393
http://git.kernel.org/stable/c/a769b05eeed7accc4019a1ed9799dd72067f1ce8
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.