Wiz Agents & Workflows are here

CVE-2024-58011
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-58011 affects the Linux kernel's platform/x86 int3472 driver. The vulnerability was discovered and disclosed on February 26, 2025, and involves a potential NULL pointer dereference in the skl_int3472_get_acpi_buffer() function. The issue occurs when devices lack an ACPI companion fwnode, which can happen when users manually bind int3472 drivers to another i2c/platform device through sysfs (NVD).

Technical details

The vulnerability is a NULL pointer dereference issue in the Linux kernel's int3472 driver. It has been assigned a CVSS v3.1 base score of 5.5 (MEDIUM) with vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. The technical root cause is that the code did not properly check if the ACPI device (adev) pointer was NULL before accessing it in the skl_int3472_get_acpi_buffer() function (NVD).

Impact

If exploited, this vulnerability could lead to a NULL pointer dereference in the kernel, potentially causing a system crash. The impact is limited to availability (denial of service) with no direct effects on confidentiality or integrity (NVD).

Mitigation and workarounds

The vulnerability has been patched by adding a check for adev being NULL and returning -ENODEV in that case. The fix has been implemented in multiple kernel versions through various patches (Kernel Patch).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23395CRITICAL9.1
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-devel-matched
NoYesMar 25, 2026
CVE-2026-23399MEDIUM6.5
  • Linux KernelLinux Kernel
  • kernel-rt-debug-modules-extra
NoYesMar 28, 2026
CVE-2026-23398MEDIUM6.5
  • Linux KernelLinux Kernel
  • kernel-64k-debug
NoYesMar 26, 2026
CVE-2026-23397MEDIUM4.4
  • Linux KernelLinux Kernel
  • kernel-rt-64k-modules-core
NoYesMar 26, 2026
CVE-2026-31788N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-fde
NoYesMar 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management