CVE-2023-3358NULL Pointer Dereference in Kernel

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 99.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 28
Latest updateJun 29

Description

A null pointer dereference was found in the Linux kernel's Integrated Sensor Hub (ISH) driver. This issue could allow a local user to crash the system.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages8 packages

NVDlinux/linux_kernel< 6.2+1
Debianlinux/linux_kernel< 5.10.178-1+3
CVEListV5linux/linux_kernelkernel 6.1-rc8
debiandebian/linux< linux 6.1.11-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rmg8-h2h6-5wwf: A null pointer dereference was found in the Linux kernel's Integrated Sensor Hub (ISH) driver2023-06-29
OSV
CVE-2023-3358: A null pointer dereference was found in the Linux kernel's Integrated Sensor Hub (ISH) driver2023-06-28

📋Vendor Advisories

3
Microsoft
A null pointer dereference was found in the Linux kernel's Integrated Sensor Hub (ISH) driver. This issue could allow a local user to crash the system.2023-06-13
Debian
CVE-2023-3358: linux - A null pointer dereference was found in the Linux kernel's Integrated Sensor Hub...2023
Red Hat
kernel: NULL pointer dereference due to missing kalloc() return value check in shtp_cl_get_dma_send_buf()2022-11-22
CVE-2023-3358 — NULL Pointer Dereference in Kernel | cvebase