First published: Wed Aug 21 2024(Updated: )
In the Linux kernel, the following vulnerability has been resolved: gsmi: fix null-deref in gsmi_get_variable We can get EFI variables without fetching the attribute, so we must allow for that in gsmi. commit 859748255b43 ("efi: pstore: Omit efivars caching EFI varstore access layer") added a new get_variable call with attr=NULL, which triggers panic in gsmi.
Credit: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | >=3.0<4.14.304 | |
Linux Linux kernel | >=4.15<4.19.271 | |
Linux Linux kernel | >=4.20<5.4.230 | |
Linux Linux kernel | >=5.5<5.10.165 | |
Linux Linux kernel | >=5.11<5.15.90 | |
Linux Linux kernel | >=5.16<6.1.8 | |
Linux Linux kernel | =6.2-rc1 | |
Linux Linux kernel | =6.2-rc2 | |
Linux Linux kernel | =6.2-rc3 | |
Linux Linux kernel | =6.2-rc4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.