cbcvebase.
CVE-2023-52459
published 2024-02-23

CVE-2023-52459: In the Linux kernel, the following vulnerability has been resolved: media: v4l: async: Fix duplicated list deletion The list deletion call dropped here is…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.0th percentile
In the Linux kernel, the following vulnerability has been resolved: media: v4l: async: Fix duplicated list deletion The list deletion call dropped here is already called from the helper function in the line before. Having a second list_del() call results in either a warning (with CONFIG_DEBUG_LIST=y): list_del corruption, c46c8198->next is LIST_POISON1 (00000100) If CONFIG_DEBUG_LIST is disabled the operation results in a kernel error due to NULL pointer dereference.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.6.15-1 (forky)linux 6.6.15-1 (forky)
linuxlinux
linuxlinux>= 28a1295795d85a25f2e7dd391c43969e95fcb341 < b7062628caeaec90e8f691ebab2d70f31b7b6b91b7062628caeaec90e8f691ebab2d70f31b7b6b91
linuxlinux>= 28a1295795d85a25f2e7dd391c43969e95fcb341 < 49d82811428469566667f22749610b8c132cdb3e49d82811428469566667f22749610b8c132cdb3e
linuxlinux>= 28a1295795d85a25f2e7dd391c43969e95fcb341 < 3de6ee94aae701fa949cd3b5df6b6a440ddfb8f23de6ee94aae701fa949cd3b5df6b6a440ddfb8f2
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 6.6.0 < 6.6.146.6.14
linuxlinux_kernel>= 6.7.0 < 6.7.26.7.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.