CVE Vulnerabilities

CVE-2024-39440

NULL Pointer Dereference

Published: Oct 09, 2024 | Modified: Oct 17, 2024
CVSS 3.x
4.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In DRM service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with System execution privileges needed.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Android Google 13.0 (including) 13.0 (including)
Android Google 14.0 (including) 14.0 (including)

Potential Mitigations

References