
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-27071 affects the Linux kernel's backlight HX8357 driver. The vulnerability was discovered and disclosed on May 1, 2024, and involves a potential NULL pointer dereference in the hx8357_probe() function. The issue occurs because the 'im' pins are optional, but the code lacked proper validation checks. This vulnerability affects Linux kernel versions from 6.8 up to (excluding) 6.8.2 (NVD).
The vulnerability exists in the backlight HX8357 driver where a NULL pointer dereference could occur due to missing validation of optional 'im' pins in the hx8357_probe() function. The issue stems from accessing the im_pins structure without first checking if it's NULL. The vulnerability has been assigned a CVSS v3.1 base score of 5.5 (Medium) with vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (NVD).
The vulnerability could allow a local attacker to cause a denial of service condition through a system crash by triggering the NULL pointer dereference in the HX8357 backlight driver (NVD).
The vulnerability requires local access and low privileges to exploit. There are no known reports of this vulnerability being exploited in the wild (NVD).
The vulnerability has been fixed in Linux kernel version 6.8.2. Ubuntu has released patches for affected versions, including fixes in version 6.8.0-35.35 for Ubuntu 24.04 LTS noble. Users should update their systems to the patched versions (Ubuntu).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."