CVE-2024-40973
Executive Summary
CVE-2024-40973: The Linux kernel media driver mtk-vcodec contains a potential null pointer dereference because the return value of devm_kzalloc() is not checked. An attacker could exploit this by supplying crafted media data, leading to a kernel crash or privilege escalation. The issue is analogous to CVE-2022-3113 and is not yet listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 5.5 (MEDIUM) - Published: 2024-07-12T13:15:18.890 - Last Modified: 2026-08-23T13:16:24.720
Original Description: In the Linux kernel, the following vulnerability has been resolved:
media: mtk-vcodec: potential null pointer deference in SCP
The return value of devm_kzalloc() needs to be checked to avoid NULL pointer deference. This is similar to CVE-2022-3113.
"It is one of the blessings of old friends that you can afford to be stupid with them."
— Ralph Emerson