CVE-2023-23000NULL Pointer Dereference in Kernel

Severity
5.5MEDIUMNVD
OSV7.8OSV6.8
EPSS
0.0%
top 98.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 1
Latest updateApr 9

Description

In the Linux kernel before 5.17, drivers/phy/tegra/xusb.c mishandles the tegra_xusb_find_port_node return value. Callers expect NULL in the error case, but an error pointer is used.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages11 packages

NVDlinux/linux_kernel< 5.17
Debianlinux/linux_kernel< 5.17.3-1+2
Ubuntulinux/linux_kernel< 5.4.0-174.193+2
debiandebian/linux< linux 5.17.3-1 (bookworm)

Patches

🔴Vulnerability Details

14
OSV
linux-azure vulnerabilities2024-04-09
OSV
linux-intel-iotg, linux-intel-iotg-5.15 vulnerabilities2024-03-28
OSV
linux-oracle, linux-oracle-5.15 vulnerabilities2024-03-25
OSV
linux-azure, linux-azure-5.4 vulnerabilities2024-03-25
OSV
linux-aws-hwe, linux-azure, linux-azure-4.15, linux-oracle vulnerabilities2024-03-25

📋Vendor Advisories

15
Ubuntu
Linux kernel (Azure) vulnerabilities2024-04-09
Ubuntu
Linux kernel (Intel IoTG) vulnerabilities2024-03-28
Ubuntu
Linux kernel vulnerabilities2024-03-25
Ubuntu
Linux kernel (Azure) vulnerabilities2024-03-25
Ubuntu
Linux kernel (Oracle) vulnerabilities2024-03-25
CVE-2023-23000 — NULL Pointer Dereference in Kernel | cvebase