cbcvebase.
CVE-2023-52649
published 2024-05-01

CVE-2023-52649: In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Avoid reading beyond LUT array When the floor LUT index (drm_fixp2int(lut_index)…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
20.0th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Avoid reading beyond LUT array When the floor LUT index (drm_fixp2int(lut_index) is the last index of the array the ceil LUT index will point to an entry beyond the array. Make sure we guard against it and use the value of the floor LUT index. v3: - Drop bits from commit description that didn't contribute anything of value

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.7.12-1 (forky)linux 6.7.12-1 (forky)
linuxlinux
linuxlinux>= db1f254f2cfaf0510ae34fa2311a8d749e95179a < 9556c167673057d48ce4a0da675026fe046654c19556c167673057d48ce4a0da675026fe046654c1
linuxlinux>= db1f254f2cfaf0510ae34fa2311a8d749e95179a < 046c1184ce60b0a37d48134f17ddbc1f32ce02bd046c1184ce60b0a37d48134f17ddbc1f32ce02bd
linuxlinux>= db1f254f2cfaf0510ae34fa2311a8d749e95179a < 92800aaeff51b8358d1e0a7eb74daf8aa2d7ce9d92800aaeff51b8358d1e0a7eb74daf8aa2d7ce9d
linuxlinux>= db1f254f2cfaf0510ae34fa2311a8d749e95179a < 2fee84030d12d9fddfa874e4562d71761a1292772fee84030d12d9fddfa874e4562d71761a129277
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 6.6 < 6.6.236.6.23
linuxlinux_kernel>= 6.7 < 6.7.116.7.11
linuxlinux_kernel>= 6.8 < 6.8.26.8.2
msrcazl3_hyperv-daemons_6.6.22.1-2_on_azure_linux_3.0
msrcazl3_hyperv-daemons_6.6.35.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.