cbcvebase.
CVE-2023-52467
published 2024-02-26

CVE-2023-52467: In the Linux kernel, the following vulnerability has been resolved: mfd: syscon: Fix null pointer dereference in of_syscon_register() kasprintf() returns a…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.28%
20.1th percentile
In the Linux kernel, the following vulnerability has been resolved: mfd: syscon: Fix null pointer dereference in of_syscon_register() kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux
linuxlinux>= e15d7f2b81d2e7d93115d46fa931b366c1cdebc2 < 927626a2073887ee30ba00633260d4d203f8e875927626a2073887ee30ba00633260d4d203f8e875
linuxlinux>= e15d7f2b81d2e7d93115d46fa931b366c1cdebc2 < c3e3a2144bf50877551138ffce9f7aa6ddfe385bc3e3a2144bf50877551138ffce9f7aa6ddfe385b
linuxlinux>= e15d7f2b81d2e7d93115d46fa931b366c1cdebc2 < 527e8c5f3d00299822612c495d5adf1f8f43c001527e8c5f3d00299822612c495d5adf1f8f43c001
linuxlinux>= e15d7f2b81d2e7d93115d46fa931b366c1cdebc2 < 3ef1130deee98997275904d9bfc37af75e1e906c3ef1130deee98997275904d9bfc37af75e1e906c
linuxlinux>= e15d7f2b81d2e7d93115d46fa931b366c1cdebc2 < 7f2c410ac470959b88e03dadd94b7a0b71df79737f2c410ac470959b88e03dadd94b7a0b71df7973
linuxlinux>= e15d7f2b81d2e7d93115d46fa931b366c1cdebc2 < 41673c66b3d0c09915698fec5c13b24336f18dd141673c66b3d0c09915698fec5c13b24336f18dd1
linuxlinux_kernel>= 0 < 5.10.209-15.10.209-1
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 5.15.0-102.1125.15.0-102.112
linuxlinux_kernel>= 5.11.0 < 5.15.1485.15.148
linuxlinux_kernel>= 5.16.0 < 6.1.756.1.75
linuxlinux_kernel>= 5.9.0 < 5.10.2095.10.209
linuxlinux_kernel>= 6.2.0 < 6.6.146.6.14
linuxlinux_kernel>= 6.7.0 < 6.7.26.7.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.1HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.