cbcvebase.
CVE-2023-52607
published 2024-03-06

CVE-2023-52607: In the Linux kernel, the following vulnerability has been resolved: powerpc/mm: Fix null-pointer dereference in pgtable_cache_add kasprintf() returns a pointer…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
14.2th percentile
In the Linux kernel, the following vulnerability has been resolved: powerpc/mm: Fix null-pointer dereference in pgtable_cache_add kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure. Ensure the allocation was successful by checking the pointer validity.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux>= a0668cdc154e54bf0c85182e0535eea237d53146 < 21e45a7b08d7cd98d6a53c5fc5111879f2d9661121e45a7b08d7cd98d6a53c5fc5111879f2d96611
linuxlinux>= a0668cdc154e54bf0c85182e0535eea237d53146 < f6781add1c311c17eff43e14c786004bbacf901ef6781add1c311c17eff43e14c786004bbacf901e
linuxlinux>= a0668cdc154e54bf0c85182e0535eea237d53146 < aa28eecb43cac6e20ef14dfc50b8892c1fbcda5baa28eecb43cac6e20ef14dfc50b8892c1fbcda5b
linuxlinux>= a0668cdc154e54bf0c85182e0535eea237d53146 < ac3ed969a40357b0542d20f096a6d43acdfa6cc7ac3ed969a40357b0542d20f096a6d43acdfa6cc7
linuxlinux>= a0668cdc154e54bf0c85182e0535eea237d53146 < d482d61025e303a2bef3733a011b6b740215cfa1d482d61025e303a2bef3733a011b6b740215cfa1
linuxlinux>= a0668cdc154e54bf0c85182e0535eea237d53146 < 145febd85c3bcc5c74d87ef9a598fc7d9122d532145febd85c3bcc5c74d87ef9a598fc7d9122d532
linuxlinux>= a0668cdc154e54bf0c85182e0535eea237d53146 < ffd29dc45bc0355393859049f6becddc3ed08f74ffd29dc45bc0355393859049f6becddc3ed08f74
linuxlinux>= a0668cdc154e54bf0c85182e0535eea237d53146 < f46c8a75263f97bda13c739ba1c90aced0d3b071f46c8a75263f97bda13c739ba1c90aced0d3b071
linuxlinux_kernel< 4.19.3074.19.307
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 5.4.0-181.2015.4.0-181.201
linuxlinux_kernel>= 0 < 5.15.0-106.1165.15.0-106.116
linuxlinux_kernel4.20 – 5.4.269
linuxlinux_kernel5.11 – 5.15.149
linuxlinux_kernel>= 5.16 < 6.1.776.1.77
linuxlinux_kernel5.5 – 5.10.210
linuxlinux_kernel>= 6.2 < 6.6.166.6.16
linuxlinux_kernel>= 6.7 < 6.7.46.7.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.