cbcvebase.
CVE-2023-52524
published 2024-03-02

CVE-2023-52524: In the Linux kernel, the following vulnerability has been resolved: net: nfc: llcp: Add lock when modifying device list The device list needs its associated…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.18%
8.1th percentile
In the Linux kernel, the following vulnerability has been resolved: net: nfc: llcp: Add lock when modifying device list The device list needs its associated lock held when modifying it, or the list could become corrupted, as syzbot discovered.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 425d9d3a92df7d96b3cfb7ee5c240293a21cbde3 < 7562780e32b84196731d57dd24563546fcf6d0827562780e32b84196731d57dd24563546fcf6d082
linuxlinux>= 5.10.188 < 5.10.1985.10.198
linuxlinux>= 5.15.121 < 5.15.1355.15.135
linuxlinux>= 5.4.251 < 5.4.2585.4.258
linuxlinux>= 6.1.39 < 6.1.576.1.57
linuxlinux>= 6.3.13 < 6.46.4
linuxlinux>= 6.4.4 < 6.56.5
linuxlinux>= 6709d4b7bc2e079241fdef15d1160581c5261c10 < 29c16c2bf5866326d5fbc4a537b3997fcac2339129c16c2bf5866326d5fbc4a537b3997fcac23391
linuxlinux>= 6709d4b7bc2e079241fdef15d1160581c5261c10 < dfc7f7a988dad34c3bf4c053124fb26aa6c5f916dfc7f7a988dad34c3bf4c053124fb26aa6c5f916
linuxlinux>= 96f2c6f272ec04083d828de46285a7d7b17d1aad < dba849cc98113b145c6e720122942c00b8012bdbdba849cc98113b145c6e720122942c00b8012bdb
linuxlinux>= dd6ff3f3862709ab1a12566e73b9d6a9b8f6e548 < 191d87a19cf1005ecf41e1ae08d74e17379e8391191d87a19cf1005ecf41e1ae08d74e17379e8391
linuxlinux>= fc8429f8d86801f092fbfbd257c3af821ac0dcd3 < 4837a192f6d06d5bb2f3f47d6ce5353ab69bf86b4837a192f6d06d5bb2f3f47d6ce5353ab69bf86b
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.205-15.10.205-1
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1
linuxlinux_kernel>= 0 < 6.5.8-16.5.8-1
linuxlinux_kernel>= 0 < 6.5.8-16.5.8-1
linuxlinux_kernel>= 0 < 4.4.0-254.2884.4.0-254.288
linuxlinux_kernel>= 0 < 4.15.0-225.2374.15.0-225.237
linuxlinux_kernel>= 5.10.188 < 5.10.1985.10.198
linuxlinux_kernel>= 5.15.121 < 5.15.1355.15.135

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.