CVE-2023-52567
published 2024-03-02CVE-2023-52567: In the Linux kernel, the following vulnerability has been resolved: serial: 8250_port: Check IRQ data before use In case the leaf driver wants to use IRQ…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
serial: 8250_port: Check IRQ data before use
In case the leaf driver wants to use IRQ polling (irq = 0) and
IIR register shows that an interrupt happened in the 8250 hardware
the IRQ data can be NULL. In such a case we need to skip the wake
event as we came to this path from the timer interrupt and quite
likely system is already awake.
Without this fix we have got an Oops:
serial8250: ttyS0 at I/O 0x3f8 (irq = 0, base_baud = 115200) is a 16550A
...
BUG: kernel NULL pointer dereference, address: 0000000000000010
RIP: 0010:serial8250_handle_irq+0x7c/0x240
Call Trace:
? serial8250_handle_irq+0x7c/0x240
? __pfx_serial8250_timeout+0x10/0x10
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.64-1 (bookworm) | linux 6.1.64-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 0ba9e3a13c6adfa99e32b2576d20820ab10ad48a < 3345cc5f02f1fb4c4dcb114706f2210d879ab933 | 3345cc5f02f1fb4c4dcb114706f2210d879ab933 |
| linux | linux | >= 0ba9e3a13c6adfa99e32b2576d20820ab10ad48a < cce7fc8b29961b64fadb1ce398dc5ff32a79643b | cce7fc8b29961b64fadb1ce398dc5ff32a79643b |
| linux | linux | >= 0bd49a043c7984c93c2a0af41222fb71c3986a4e < c334650150c29234b0923476f51573ae1b2f252a | c334650150c29234b0923476f51573ae1b2f252a |
| linux | linux | >= 4.14.315 < 4.14.327 | 4.14.327 |
| linux | linux | >= 4.19.283 < 4.19.296 | 4.19.296 |
| linux | linux | >= 424cf29296354d7b9c6c038aaa7bb71782100851 < 2b837f13a818f96304736453ac53b66a70aaa4f2 | 2b837f13a818f96304736453ac53b66a70aaa4f2 |
| linux | linux | >= 5.10.180 < 5.10.198 | 5.10.198 |
| linux | linux | >= 5.15.111 < 5.15.134 | 5.15.134 |
| linux | linux | >= 5.4.243 < 5.4.258 | 5.4.258 |
| linux | linux | >= 572d48361aa0a6e6f16c1470e5407de183493d0c < bf3c728e3692cc6d998874f0f27d433117348742 | bf3c728e3692cc6d998874f0f27d433117348742 |
| linux | linux | >= 6.1.28 < 6.1.56 | 6.1.56 |
| linux | linux | >= 6.2.15 < 6.3 | 6.3 |
| linux | linux | >= 6.3.2 < 6.4 | 6.4 |
| linux | linux | >= 727e92fe13e81c6088a88d83e466b2b1b553c4e3 < e14f68a48fd445a083ac0750fafcb064df5f18f7 | e14f68a48fd445a083ac0750fafcb064df5f18f7 |
| linux | linux | >= d5d628fea5f6181809a9d61b04de6ade53277684 < e14afa4450cb7e4cf93e993a765801203d41d014 | e14afa4450cb7e4cf93e993a765801203d41d014 |
| linux | linux | >= edfe57aedff4ecf3606533aabf8ecf7676c3c5d9 < ee5732caaffba3a37e753fdb89b4958db9a61847 | ee5732caaffba3a37e753fdb89b4958db9a61847 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.205-1 | 5.10.205-1 |
| linux | linux_kernel | >= 0 < 6.1.64-1 | 6.1.64-1 |
| linux | linux_kernel | >= 0 < 6.5.6-1 | 6.5.6-1 |
| linux | linux_kernel | >= 0 < 6.5.6-1 | 6.5.6-1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-68m6-x9cq-fjwx: In the Linux kernel, the following vulnerability has been resolved:
serial: 8250_port: Check IRQ data before use
In case the leaf driver wants to us
ghsa_unreviewed·2024-03-03
CVE-2023-52567 [MEDIUM] CWE-476 GHSA-68m6-x9cq-fjwx: In the Linux kernel, the following vulnerability has been resolved:
serial: 8250_port: Check IRQ data before use
In case the leaf driver wants to us
In the Linux kernel, the following vulnerability has been resolved:
serial: 8250_port: Check IRQ data before use
In case the leaf driver wants to use IRQ polling (irq = 0) and
IIR register shows that an interrupt happened in the 8250 hardware
the IRQ data can be NULL. In such a case we need to skip the wake
event as we came to this path from the timer interrupt and quite
likely system is already awake.
Without this fix we have got an Oops:
serial8250: ttyS0 at I/O 0x3f8 (irq = 0, base_baud = 115200) is a 16550A
...
BUG: kernel NULL pointer dereference, address: 0000000000000010
RIP: 0010:serial8250_handle_irq+0x7c/0x240
Call Trace:
? serial8250_handle_irq+0x7c/0x240
? __pfx_serial8250_timeout+0x10/0x10
OSV
CVE-2023-52567: In the Linux kernel, the following vulnerability has been resolved: serial: 8250_port: Check IRQ data before use In case the leaf driver wants to use
osv·2024-03-02·CVSS 5.5
CVE-2023-52567 [MEDIUM] CVE-2023-52567: In the Linux kernel, the following vulnerability has been resolved: serial: 8250_port: Check IRQ data before use In case the leaf driver wants to use
In the Linux kernel, the following vulnerability has been resolved: serial: 8250_port: Check IRQ data before use In case the leaf driver wants to use IRQ polling (irq = 0) and IIR register shows that an interrupt happened in the 8250 hardware the IRQ data can be NULL. In such a case we need to skip the wake event as we came to this path from the timer interrupt and quite likely system is already awake. Without this fix we have got an Oops: serial8250: ttyS0 at I/O 0x3f8 (irq = 0, base_baud = 115200) is a 16550A ... BUG: kernel NULL pointer dereference, address: 0000000000000010 RIP: 0010:serial8250_handle_irq+0x7c/0x240 Call Trace: ? serial8250_handle_irq+0x7c/0x240 ? __pfx_serial8250_timeout+0x10/0x10
Red Hat
kernel: serial: 8250_port: IRQ data NULL pointer dereference
vendor_redhat·2024-03-02·CVSS 5.5
CVE-2023-52567 [MEDIUM] CWE-476 kernel: serial: 8250_port: IRQ data NULL pointer dereference
kernel: serial: 8250_port: IRQ data NULL pointer dereference
In the Linux kernel, the following vulnerability has been resolved:
serial: 8250_port: Check IRQ data before use
In case the leaf driver wants to use IRQ polling (irq = 0) and
IIR register shows that an interrupt happened in the 8250 hardware
the IRQ data can be NULL. In such a case we need to skip the wake
event as we came to this path from the timer interrupt and quite
likely system is already awake.
Without this fix we have got an Oops:
serial8250: ttyS0 at I/O 0x3f8 (irq = 0, base_baud = 115200) is a 16550A
...
BUG: kernel NULL pointer dereference, address: 0000000000000010
RIP: 0010:serial8250_handle_irq+0x7c/0x240
Call Trace:
? serial8250_handle_irq+0x7c/0x240
? __pfx_serial8250_timeout+0x10/0x10
Package: kernel (Red Hat
Debian
CVE-2023-52567: linux - In the Linux kernel, the following vulnerability has been resolved: serial: 825...
vendor_debian·2023·CVSS 5.5
CVE-2023-52567 [MEDIUM] CVE-2023-52567: linux - In the Linux kernel, the following vulnerability has been resolved: serial: 825...
In the Linux kernel, the following vulnerability has been resolved: serial: 8250_port: Check IRQ data before use In case the leaf driver wants to use IRQ polling (irq = 0) and IIR register shows that an interrupt happened in the 8250 hardware the IRQ data can be NULL. In such a case we need to skip the wake event as we came to this path from the timer interrupt and quite likely system is already awake. Without this fix we have got an Oops: serial8250: ttyS0 at I/O 0x3f8 (irq = 0, base_baud = 115200) is a 16550A ... BUG: kernel NULL pointer dereference, address: 0000000000000010 RIP: 0010:serial8250_handle_irq+0x7c/0x240 Call Trace: ? serial8250_handle_irq+0x7c/0x240 ? __pfx_serial8250_timeout+0x10/0x10
Scope: local
bookworm: resolved (fixed in 6.1.64-1)
bullseye: resolved (fixed in 5.10.20
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/2b837f13a818f96304736453ac53b66a70aaa4f2https://git.kernel.org/stable/c/3345cc5f02f1fb4c4dcb114706f2210d879ab933https://git.kernel.org/stable/c/bf3c728e3692cc6d998874f0f27d433117348742https://git.kernel.org/stable/c/c334650150c29234b0923476f51573ae1b2f252ahttps://git.kernel.org/stable/c/cce7fc8b29961b64fadb1ce398dc5ff32a79643bhttps://git.kernel.org/stable/c/e14afa4450cb7e4cf93e993a765801203d41d014https://git.kernel.org/stable/c/e14f68a48fd445a083ac0750fafcb064df5f18f7https://git.kernel.org/stable/c/ee5732caaffba3a37e753fdb89b4958db9a61847https://git.kernel.org/stable/c/2b837f13a818f96304736453ac53b66a70aaa4f2https://git.kernel.org/stable/c/3345cc5f02f1fb4c4dcb114706f2210d879ab933https://git.kernel.org/stable/c/bf3c728e3692cc6d998874f0f27d433117348742https://git.kernel.org/stable/c/c334650150c29234b0923476f51573ae1b2f252ahttps://git.kernel.org/stable/c/cce7fc8b29961b64fadb1ce398dc5ff32a79643bhttps://git.kernel.org/stable/c/e14afa4450cb7e4cf93e993a765801203d41d014https://git.kernel.org/stable/c/e14f68a48fd445a083ac0750fafcb064df5f18f7https://git.kernel.org/stable/c/ee5732caaffba3a37e753fdb89b4958db9a61847
2024-03-02
Published