CVE-2024-26975: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: powercap: intel_rapl: Fix a NULL pointer dereference A NULL pointer dereference is triggered when probing the MMIO RAPL driver on platforms with CPU ID not listed in intel_rapl_common CPU model list. This is because the intel_rapl_common module still probes on such platforms even if 'defaults_msr' is not set after commit 1488ac990ac8 ("powercap: intel_rapl: Allow probing without CPUID match"). Thus the MMIO RAPL rp->priv->defaults is NULL when registering to RAPL framework. Fix the problem by adding sanity check to ensure rp->priv->rapl_defaults is always valid.
Affected products
- Linux Linux Kernel: from 6.5, before 6.6.24 (fixed in 6.6.24); from 6.7, before 6.7.12 (fixed in 6.7.12); from 6.8, before 6.8.3 (fixed in 6.8.3)
Published 2024-05-01. Last modified 2026-06-17.