Security Advisory

CVE-2024-38573

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-06-19 13:35:38
Last updated 2026-05-11 20:19:19
Assigner Linux
State PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: cppc_cpufreq: Fix possible null pointer dereference cppc_cpufreq_get_rate() and hisi_cppc_cpufreq_get_rate() can be called from different places with various parameters. So cpufreq_cpu_get() can return null as policy in some circumstances. Fix this bug by adding null return check. Found by Linux Verification Center (linuxtesting.org) with SVACE.