CVE-2024-49962: ACPICA: check null return of ACPI_ALLOCATE_ZEROED() in acpi_db_convert_to_package()
ACPICA: check null return of ACPIALLOCATEZEROED() in acpidbconverttopackage()
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49962?
CVE-2024-49962 has been assigned a medium severity score due to the potential for NULL pointer dereference.
How do I fix CVE-2024-49962?
To fix CVE-2024-49962, it is recommended to upgrade to a patched version of the Linux kernel: 6.1.123-1 or later.
Which versions of the Linux kernel are affected by CVE-2024-49962?
CVE-2024-49962 affects Linux kernel versions prior to 5.10.227, and between 5.11 and 5.15.168, 5.16 and 6.1.113, 6.2 and 6.6.55, 6.7 and 6.10.14, and 6.11 up to 6.11.3.
What systems are impacted by CVE-2024-49962?
CVE-2024-49962 impacts any systems running the affected versions of the Linux kernel.
Is there a workaround for CVE-2024-49962 if I cannot upgrade?
Currently, there are no known workarounds for CVE-2024-49962, so applying the patch is the best approach.