CVE-2023-52512
published 2024-03-02CVE-2023-52512: In the Linux kernel, the following vulnerability has been resolved: pinctrl: nuvoton: wpcm450: fix out of bounds write Write into 'pctrl->gpio_bank' happens…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
pinctrl: nuvoton: wpcm450: fix out of bounds write
Write into 'pctrl->gpio_bank' happens before the check for GPIO index
validity, so out of bounds write may happen.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.64-1 (bookworm) | linux 6.1.64-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= a1d1e0e3d80a870cc37a6c064994b89e963d2b58 < 6c18c386fd13dbb3ff31a1086dabb526780d9bda | 6c18c386fd13dbb3ff31a1086dabb526780d9bda |
| linux | linux | >= a1d1e0e3d80a870cc37a6c064994b89e963d2b58 < c9d7cac0fd27c74dd368e80dc4b5d0f9f2e13cf8 | c9d7cac0fd27c74dd368e80dc4b5d0f9f2e13cf8 |
| linux | linux | >= a1d1e0e3d80a870cc37a6c064994b89e963d2b58 < 87d315a34133edcb29c4cadbf196ec6c30dfd47b | 87d315a34133edcb29c4cadbf196ec6c30dfd47b |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.1.64-1 | 6.1.64-1 |
| linux | linux_kernel | >= 0 < 6.5.8-1 | 6.5.8-1 |
| linux | linux_kernel | >= 0 < 6.5.8-1 | 6.5.8-1 |
| linux | linux_kernel | >= 5.18 < 6.1.59 | 6.1.59 |
| linux | linux_kernel | >= 6.2 < 6.5.8 | 6.5.8 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8j2x-98w6-cr3m: In the Linux kernel, the following vulnerability has been resolved:
pinctrl: nuvoton: wpcm450: fix out of bounds write
Write into 'pctrl->gpio_bank'
ghsa_unreviewed·2024-03-03
CVE-2023-52512 [MEDIUM] CWE-787 GHSA-8j2x-98w6-cr3m: In the Linux kernel, the following vulnerability has been resolved:
pinctrl: nuvoton: wpcm450: fix out of bounds write
Write into 'pctrl->gpio_bank'
In the Linux kernel, the following vulnerability has been resolved:
pinctrl: nuvoton: wpcm450: fix out of bounds write
Write into 'pctrl->gpio_bank' happens before the check for GPIO index
validity, so out of bounds write may happen.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
OSV
CVE-2023-52512: In the Linux kernel, the following vulnerability has been resolved: pinctrl: nuvoton: wpcm450: fix out of bounds write Write into 'pctrl->gpio_bank' h
osv·2024-03-02·CVSS 5.5
CVE-2023-52512 [MEDIUM] CVE-2023-52512: In the Linux kernel, the following vulnerability has been resolved: pinctrl: nuvoton: wpcm450: fix out of bounds write Write into 'pctrl->gpio_bank' h
In the Linux kernel, the following vulnerability has been resolved: pinctrl: nuvoton: wpcm450: fix out of bounds write Write into 'pctrl->gpio_bank' happens before the check for GPIO index validity, so out of bounds write may happen. Found by Linux Verification Center (linuxtesting.org) with SVACE.
Red Hat
kernel: pinctrl: nuvoton: wpcm450: fix out of bounds write
vendor_redhat·2024-03-02·CVSS 5.5
CVE-2023-52512 [MEDIUM] CWE-787 kernel: pinctrl: nuvoton: wpcm450: fix out of bounds write
kernel: pinctrl: nuvoton: wpcm450: fix out of bounds write
In the Linux kernel, the following vulnerability has been resolved:
pinctrl: nuvoton: wpcm450: fix out of bounds write
Write into 'pctrl->gpio_bank' happens before the check for GPIO index
validity, so out of bounds write may happen.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
An out of bounds write was found in drivers/pinctrl/nuvoton/pinctrl-wpcm450.c in the Linux kernel. This may cause a crash.
Statement: Red Hat has protection mechanisms in place against buffer overflows such as FORTIFY_SOURCE, Position Independent Executables, or Stack Smashing Protection.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red H
Debian
CVE-2023-52512: linux - In the Linux kernel, the following vulnerability has been resolved: pinctrl: nu...
vendor_debian·2023·CVSS 5.5
CVE-2023-52512 [MEDIUM] CVE-2023-52512: linux - In the Linux kernel, the following vulnerability has been resolved: pinctrl: nu...
In the Linux kernel, the following vulnerability has been resolved: pinctrl: nuvoton: wpcm450: fix out of bounds write Write into 'pctrl->gpio_bank' happens before the check for GPIO index validity, so out of bounds write may happen. Found by Linux Verification Center (linuxtesting.org) with SVACE.
Scope: local
bookworm: resolved (fixed in 6.1.64-1)
bullseye: resolved
forky: resolved (fixed in 6.5.8-1)
sid: resolved (fixed in 6.5.8-1)
trixie: resolved (fixed in 6.5.8-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/6c18c386fd13dbb3ff31a1086dabb526780d9bdahttps://git.kernel.org/stable/c/87d315a34133edcb29c4cadbf196ec6c30dfd47bhttps://git.kernel.org/stable/c/c9d7cac0fd27c74dd368e80dc4b5d0f9f2e13cf8https://git.kernel.org/stable/c/6c18c386fd13dbb3ff31a1086dabb526780d9bdahttps://git.kernel.org/stable/c/87d315a34133edcb29c4cadbf196ec6c30dfd47bhttps://git.kernel.org/stable/c/c9d7cac0fd27c74dd368e80dc4b5d0f9f2e13cf8
2024-03-02
Published