Bug 1223201 (CVE-2024-26908) - VUL-0: REJECTED: CVE-2024-26908: kernel: x86/xen: Add some null pointer checking to smp.c
Summary: VUL-0: REJECTED: CVE-2024-26908: kernel: x86/xen: Add some null pointer check...
Status: RESOLVED INVALID
Alias: CVE-2024-26908
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/402403/
Whiteboard: CVSSv3.1:SUSE:CVE-2024-26908:5.5:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2024-04-22 09:38 UTC by SMASH SMASH
Modified: 2024-05-15 16:18 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 2 Jürgen Groß 2024-04-29 11:17:09 UTC
I don't see any security aspect for the issue the patch is fixing.

It is nothing an unprivileged user could trigger, which is the reason why we in the Xen security team did _not_ issue an XSA for this fix.

I think this CVE should be disputed.