CVE-2024-58021: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: HID: winwing: Add NULL check in winwing_init_led() devm_kasprintf() can return a NULL pointer on failure,but this returned value in winwing_init_led() is not checked. Add NULL check in winwing_init_led(), to handle kernel NULL pointer dereference error.

Affected products

  • Linux Linux Kernel: from 6.10, before 6.12.16 (fixed in 6.12.16); from 6.13, before 6.13.4 (fixed in 6.13.4); version 6.14 only

Published 2025-02-27. Last modified 2026-06-17.