CVE-2024-46721: apparmor: fix possible NULL pointer dereference
Published Sep 18, 2024
·Updated
apparmor: fix possible NULL pointer dereference
Affected Software
14 affected componentsFixes available
Linux Linux kernel<4.19.322
Linux Linux kernel>=4.20<5.4.284
Linux Linux kernel>=5.5<5.10.226
Linux Linux kernel>=5.11<5.15.167
Linux Linux kernel>=5.16<6.1.109
Linux Linux kernel>=6.2<6.6.50
Linux Linux kernel>=6.7<6.10.9
debian/linux<=5.10.223-1
5.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
debian/linux-6.1
6.1.129-1~deb11u1
Microsoft cbl2 kernel 5.15.164.1-1
Microsoft cbl2 kernel 5.15.167.1-1
Microsoft azl3 kernel 6.6.47.1-1
Microsoft cbl2 kernel 5.15.164.1-1
Microsoft azl3 kernel 6.6.51.1-5
Remediation
Event History
Sep 18, 2024
CVE Published
via MITRE·06:32 AM
Data Sourced
via MITRE·06:32 AM
Description
Data Sourced
via NVD·07:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Oct 12, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Updated
via Microsoft·07:00 AM
Description
May 1, 2025
Data Sourced
via Ubuntu·12:36 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-46721?
CVE-2024-46721 has been rated as having a medium severity level due to the potential for NULL pointer dereference in the Linux kernel.
2
How do I fix CVE-2024-46721?
To mitigate CVE-2024-46721, update your Linux kernel to a version that includes the patch, such as 5.10.226-1 or later.
3
Which Linux kernel versions are affected by CVE-2024-46721?
CVE-2024-46721 affects Linux kernel versions up to and including 5.10.223-1 and older versions of 4.19.322.
4
What type of vulnerability is CVE-2024-46721?
CVE-2024-46721 is a memory management vulnerability related to possible NULL pointer dereference in the AppArmor subsystem of the Linux kernel.
5
Is CVE-2024-46721 specific to any particular Linux distribution?
CVE-2024-46721 can affect various Linux distributions that utilize vulnerable versions of the Linux kernel, notably Debian systems.