NULL Pointer Dereference Affecting rtla package, versions <0:5.14.0-427.33.1.el9_4


Severity

Recommended
high

Based on AlmaLinux security rating.

Threat Intelligence

EPSS
0.04% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about NULL Pointer Dereference vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-ALMALINUX9-RTLA-8330503
  • published4 Nov 2024
  • disclosed28 Aug 2024

Introduced: 28 Aug 2024

CVE-2024-26855  (opens in a new tab)
CWE-476  (opens in a new tab)

How to fix?

Upgrade AlmaLinux:9 rtla to version 0:5.14.0-427.33.1.el9_4 or higher.
This issue was patched in ALSA-2024:5928.

NVD Description

Note: Versions mentioned in the description apply only to the upstream rtla package and not the rtla package as distributed by AlmaLinux. See How to fix? for AlmaLinux:9 relevant fixed versions and status.

In the Linux kernel, the following vulnerability has been resolved:

net: ice: Fix potential NULL pointer dereference in ice_bridge_setlink()

The function ice_bridge_setlink() may encounter a NULL pointer dereference if nlmsg_find_attr() returns NULL and br_spec is dereferenced subsequently in nla_for_each_nested(). To address this issue, add a check to ensure that br_spec is not NULL before proceeding with the nested attribute iteration.

CVSS Scores

version 3.1