Kernel Vulnerability in Linux Affects HID Winwing Product
CVE-2024-58021

Currently unrated

Key Information:

Vendor
Linux
Status
Vendor
CVE Published:
27 February 2025

Summary

A vulnerability exists in the Linux kernel related to the HID Winwing component. The issue arises in the winwing_init_led() function where the output of devm_kasprintf() is not checked for NULL values. This oversight could potentially lead to a NULL pointer dereference, exposing the system to stability issues and security risks. Implementing a NULL check in winwing_init_led() is necessary to safely handle such failures and bolster system resilience.

Affected Version(s)

Linux 266c990debad2f9589c7a412e897a8e312b09766

Linux 266c990debad2f9589c7a412e897a8e312b09766 < 4001f6f79183b8868d80dd2036dfb4ea3d325e8f

Linux 266c990debad2f9589c7a412e897a8e312b09766 < 45ab5166a82d038c898985b0ad43ead69c1f9573

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.