CVE-2024-39470: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: eventfs: Fix a possible null pointer dereference in eventfs_find_events() In function eventfs_find_events,there is a potential null pointer that may be caused by calling update_events_attr which will perform some operations on the members of the ei struct when ei is NULL. Hence,When ei->is_freed is set,return NULL directly.

Affected products

  • Linux Linux Kernel: from 6.6.18, before 6.6.34 (fixed in 6.6.34); from 6.8, before 6.9.5 (fixed in 6.9.5)

Published 2024-06-25. Last modified 2026-06-17.