CVE-2024-24856: Openanolis Anolis OS
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The memory allocation function ACPI_ALLOCATE_ZEROED does not guarantee a successful allocation, but the subsequent code directly dereferences the pointer that receives it, which may lead to null pointer dereference. To fix this issue, a null pointer check should be added. If it is null, return exception code AE_NO_MEMORY.
Affected products
- Openanolis Anolis OS: from v4.4, before v6.9 (fixed in v6.9)
Published 2024-04-17. Last modified 2026-06-17.