CVE-2023-22998Interpretation Conflict in Kernel

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 94.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 28
Latest updateFeb 14

Description

In the Linux kernel before 6.0.3, drivers/gpu/drm/virtio/virtgpu_object.c misinterprets the drm_gem_shmem_get_sg_table return value (expects it to be NULL in the error case, whereas it is actually an error pointer).

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages10 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3mg2-w983-r26q: In the Linux kernel before 62023-02-28
OSV
CVE-2023-22998: In the Linux kernel before 62023-02-28

📋Vendor Advisories

4
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS2024-02-14
Red Hat
kernel: drm/virtio: improper return value check in virtio_gpu_object_shmem_init()2023-02-28
Microsoft
In the Linux kernel before 6.0.3 drivers/gpu/drm/virtio/virtgpu_object.c misinterprets the drm_gem_shmem_get_sg_table return value (expects it to be NULL in the error case whereas it is actually an er2023-02-14
Debian
CVE-2023-22998: linux - In the Linux kernel before 6.0.3, drivers/gpu/drm/virtio/virtgpu_object.c misint...2023

💬Community

1
Bugzilla
CVE-2023-22998 kernel: drm/virtio: improper return value check in virtio_gpu_object_shmem_init()2023-03-28