CVE-2024-49962: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ACPICA: check null return of ACPI_ALLOCATE_ZEROED() in acpi_db_convert_to_package() ACPICA commit 4d4547cf13cca820ff7e0f859ba83e1a610b9fd0 ACPI_ALLOCATE_ZEROED() may fail, elements might be NULL and will cause NULL pointer dereference later. [ rjw: Subject and changelog edits ]
Affected products
- Linux Linux Kernel: before 5.10.227 (fixed in 5.10.227); from 5.11, before 5.15.168 (fixed in 5.15.168); from 5.16, before 6.1.113 (fixed in 6.1.113); from 6.2, before 6.6.55 (fixed in 6.6.55); from 6.7, before 6.10.14 (fixed in 6.10.14); from 6.11, before 6.11.3 (fixed in 6.11.3)
Published 2024-10-21. Last modified 2026-06-17.