CVE-2024-42144: thermal/drivers/mediatek/lvts_thermal: Check NULL ptr on lvts_data
Published Jul 30, 2024
·Updated
In the Linux kernel, the following vulnerability has been resolved:
thermal/drivers/mediatek/lvtsthermal: Check NULL ptr on lvtsdata
Verify that lvtsdata is not NULL before using it.
Affected Software
3 affected componentsFixes available
Linux Linux kernel<6.6.39
Linux Linux kernel>=6.7<6.9.9
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
Remediation
Event History
Jul 30, 2024
CVE Published
via MITRE·07:46 AM
Data Sourced
via MITRE·07:46 AM
Description
Dec 15, 2024
Data Sourced
via Ubuntu·12:32 PM
RemedyDescriptionSeverityAffected Software
Mar 30, 2025
Data Sourced
via Debian·12:25 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-42144?
CVE-2024-42144 has a moderate severity rating due to potential impacts on system stability.
2
How do I fix CVE-2024-42144?
To fix CVE-2024-42144, update the Linux kernel to one of the following versions: 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.128-1, 6.12.12-1, or 6.12.15-1.
3
Which systems are affected by CVE-2024-42144?
CVE-2024-42144 affects various Linux kernel versions, specifically those below 6.6.39.
4
What does CVE-2024-42144 address?
CVE-2024-42144 addresses a NULL pointer dereference in the lvts_thermal driver for Mediatek.
5
When was CVE-2024-42144 disclosed?
CVE-2024-42144 was disclosed as part of ongoing updates to the Linux kernel and recent patches.