cbcvebase.
CVE-2023-52567
published 2024-03-02

CVE-2023-52567: In the Linux kernel, the following vulnerability has been resolved: serial: 8250_port: Check IRQ data before use In case the leaf driver wants to use IRQ…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.4th percentile
In the Linux kernel, the following vulnerability has been resolved: serial: 8250_port: Check IRQ data before use In case the leaf driver wants to use IRQ polling (irq = 0) and IIR register shows that an interrupt happened in the 8250 hardware the IRQ data can be NULL. In such a case we need to skip the wake event as we came to this path from the timer interrupt and quite likely system is already awake. Without this fix we have got an Oops: serial8250: ttyS0 at I/O 0x3f8 (irq = 0, base_baud = 115200) is a 16550A ... BUG: kernel NULL pointer dereference, address: 0000000000000010 RIP: 0010:serial8250_handle_irq+0x7c/0x240 Call Trace: ? serial8250_handle_irq+0x7c/0x240 ? __pfx_serial8250_timeout+0x10/0x10

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 0ba9e3a13c6adfa99e32b2576d20820ab10ad48a < 3345cc5f02f1fb4c4dcb114706f2210d879ab9333345cc5f02f1fb4c4dcb114706f2210d879ab933
linuxlinux>= 0ba9e3a13c6adfa99e32b2576d20820ab10ad48a < cce7fc8b29961b64fadb1ce398dc5ff32a79643bcce7fc8b29961b64fadb1ce398dc5ff32a79643b
linuxlinux>= 0bd49a043c7984c93c2a0af41222fb71c3986a4e < c334650150c29234b0923476f51573ae1b2f252ac334650150c29234b0923476f51573ae1b2f252a
linuxlinux>= 4.14.315 < 4.14.3274.14.327
linuxlinux>= 4.19.283 < 4.19.2964.19.296
linuxlinux>= 424cf29296354d7b9c6c038aaa7bb71782100851 < 2b837f13a818f96304736453ac53b66a70aaa4f22b837f13a818f96304736453ac53b66a70aaa4f2
linuxlinux>= 5.10.180 < 5.10.1985.10.198
linuxlinux>= 5.15.111 < 5.15.1345.15.134
linuxlinux>= 5.4.243 < 5.4.2585.4.258
linuxlinux>= 572d48361aa0a6e6f16c1470e5407de183493d0c < bf3c728e3692cc6d998874f0f27d433117348742bf3c728e3692cc6d998874f0f27d433117348742
linuxlinux>= 6.1.28 < 6.1.566.1.56
linuxlinux>= 6.2.15 < 6.36.3
linuxlinux>= 6.3.2 < 6.46.4
linuxlinux>= 727e92fe13e81c6088a88d83e466b2b1b553c4e3 < e14f68a48fd445a083ac0750fafcb064df5f18f7e14f68a48fd445a083ac0750fafcb064df5f18f7
linuxlinux>= d5d628fea5f6181809a9d61b04de6ade53277684 < e14afa4450cb7e4cf93e993a765801203d41d014e14afa4450cb7e4cf93e993a765801203d41d014
linuxlinux>= edfe57aedff4ecf3606533aabf8ecf7676c3c5d9 < ee5732caaffba3a37e753fdb89b4958db9a61847ee5732caaffba3a37e753fdb89b4958db9a61847
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.205-15.10.205-1
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1
linuxlinux_kernel>= 0 < 6.5.6-16.5.6-1
linuxlinux_kernel>= 0 < 6.5.6-16.5.6-1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.