Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: nbd: null check for nla_nest_start nla_nest_start() may fail and return NULL. Insert a check and set errno based on other call sites within the same source code.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.12, < 5.4.273 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/31edf4bbe0ba27fd03ac7d87eb2ee3d2a231af6dPatch
- https://git.kernel.org/stable/c/44214d744be32a4769faebba764510888f1eb19ePatch
- https://git.kernel.org/stable/c/4af837db0fd3679fabc7b7758397090b0c06dcedPatch
- https://git.kernel.org/stable/c/96436365e5d80d0106ea785a4f80a58e7c9edff8Patch
- https://git.kernel.org/stable/c/98e60b538e66c90b9a856828c71d4e975ebfa797Patch
- https://git.kernel.org/stable/c/b7f5aed55829f376e4f7e5ea5b80ccdcb023e983Patch
- https://git.kernel.org/stable/c/ba6a9970ce9e284cbc04099361c58731e308596aPatch
- https://git.kernel.org/stable/c/e803040b368d046434fbc8a91945c690332c4fcfPatch
- https://git.kernel.org/stable/c/31edf4bbe0ba27fd03ac7d87eb2ee3d2a231af6dPatch
- https://git.kernel.org/stable/c/44214d744be32a4769faebba764510888f1eb19ePatch
- https://git.kernel.org/stable/c/4af837db0fd3679fabc7b7758397090b0c06dcedPatch
- https://git.kernel.org/stable/c/96436365e5d80d0106ea785a4f80a58e7c9edff8Patch
- https://git.kernel.org/stable/c/98e60b538e66c90b9a856828c71d4e975ebfa797Patch
- https://git.kernel.org/stable/c/b7f5aed55829f376e4f7e5ea5b80ccdcb023e983Patch
- https://git.kernel.org/stable/c/ba6a9970ce9e284cbc04099361c58731e308596aPatch
FAQ
What is CVE-2024-27025?
CVE-2024-27025 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: nbd: null check for nla_nest_start nla_nest_start() may fail and return NULL. Insert a check and set errno based on other call sit...
How severe is CVE-2024-27025?
CVE-2024-27025 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-27025?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux.