CVE-2024-49879
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-49879 is a vulnerability in the Linux kernel's OMAP DRM (Direct Rendering Manager) driver that was discovered and disclosed on October 21, 2024. The vulnerability stems from a missing check for the allocorderedworkqueue function return value in the OMAP DRM driver, which could potentially lead to a NULL pointer dereference (NVD). This vulnerability affects Linux kernel versions from 4.11 up to versions before 5.10.227, 5.15.168, 6.1.113, and 6.6.55.

Technical details

The vulnerability exists in the OMAP DRM driver's initialization routine where the allocorderedworkqueue function is called without proper error checking. The function may return a NULL pointer, and without proper validation, this could lead to a NULL pointer dereference. The issue has been assigned a CVSS v3.1 base score of 5.5 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating local access is required and the primary impact is on system availability (NVD).

Impact

The vulnerability can cause a NULL pointer dereference in the Linux kernel's OMAP DRM driver, which could lead to system crashes or denial of service conditions. The impact is limited to systems using the affected OMAP DRM driver components (NVD).

Mitigation and workarounds

The vulnerability has been fixed through a patch that adds proper error checking for the allocorderedworkqueue function return value. The fix has been implemented across multiple Linux kernel versions, including backports to stable branches. Users should update their Linux kernel to versions 5.10.227, 5.15.168, 6.1.113, 6.6.55 or later to address this vulnerability (Kernel Patch).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40343MEDIUM6.4
  • Linux KernelLinux Kernel
  • linux-iot
NoYesDec 09, 2025
CVE-2025-40342MEDIUM6.4
  • Linux KernelLinux Kernel
  • kernel-rt-devel-matched
NoYesDec 09, 2025
CVE-2025-40340MEDIUM6.4
  • Linux KernelLinux Kernel
  • linux-hwe
NoYesDec 09, 2025
CVE-2025-40341MEDIUM5.1
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-core
NoYesDec 09, 2025
CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • libperf-devel
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management