In the Linux kernel, the following vulnerability has been resolved:
efi/fdt: fix panic when no valid fdt found
setup_arch() would invoke efi_init()->efi_get_fdt_params(). If no valid fdt found then initial_boot_params will be null. So we should stop further fdt processing here. I encountered this issue on risc-v.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-debuginfo-common-x86_64Upgrade kernel-toolsUpgrade bpftool-debuginfoUpgrade kernel-debuginfo-common-aarch64Upgrade python-perfUpgrade bpftoolUpgrade perfUpgrade kernel-debuginfoUpgrade kernel-develUpgrade kernel-tools-develUpgrade python-perf-debuginfoUpgrade kernel-tools-debuginfoUpgrade kernelUpgrade kernel-headersUpgrade perf-debuginfo | Aug 2, 2024 | Mar 15, 2024 |
| Debian | — | Upgrade linux | Jul 30, 2024 | Mar 15, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 15, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub