Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: phy: realtek: usb: fix NULL deref in rtk_usb3phy_probe In rtk_usb3phy_probe() devm_kzalloc() may return NULL but this returned value is not checked.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.6, < 6.11.11 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/258ea41c926b7b3a16d0d7aa210a1401c4a1601b
- https://git.kernel.org/stable/c/48d52d3168749e10c1c37cd4ceccd18625851741Patch
- https://git.kernel.org/stable/c/776f13ad1f88485206f1dca5ef138553106950e5Patch
- https://git.kernel.org/stable/c/bf373d2919d98f3d1fe1b19a0304f72fe74386d9Patch
- https://git.kernel.org/stable/c/e27877990e54bfe4246dd850f7ec8646c999ce58
FAQ
What is CVE-2024-53204?
CVE-2024-53204 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: phy: realtek: usb: fix NULL deref in rtk_usb3phy_probe In rtk_usb3phy_probe() devm_kzalloc() may return NULL but this returned val...
How severe is CVE-2024-53204?
CVE-2024-53204 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-53204?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.