cbcvebase.
CVE-2023-52683
published 2024-05-17

CVE-2023-52683: In the Linux kernel, the following vulnerability has been resolved: ACPI: LPIT: Avoid u32 multiplication overflow In lpit_update_residency() there is a…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.3th percentile
In the Linux kernel, the following vulnerability has been resolved: ACPI: LPIT: Avoid u32 multiplication overflow In lpit_update_residency() there is a possibility of overflow in multiplication, if tsc_khz is large enough (> UINT_MAX/1000). Change multiplication to mul_u32_u32(). Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected

22 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux
linuxlinux>= eeb2d80d502af28e5660ff4bbe00f90ceb82c2db < 647d1d50c31e60ef9ccb9756a8fdf863329f7aee647d1d50c31e60ef9ccb9756a8fdf863329f7aee
linuxlinux>= eeb2d80d502af28e5660ff4bbe00f90ceb82c2db < 6c38e791bde07d6ca2a0a619ff9b6837e0d5f9ad6c38e791bde07d6ca2a0a619ff9b6837e0d5f9ad
linuxlinux>= eeb2d80d502af28e5660ff4bbe00f90ceb82c2db < f39c3d578c7d09a18ceaf56750fc7f20b02ada63f39c3d578c7d09a18ceaf56750fc7f20b02ada63
linuxlinux>= eeb2d80d502af28e5660ff4bbe00f90ceb82c2db < c1814a4ffd016ce5392c6767d22ef3aa2f0d4bd1c1814a4ffd016ce5392c6767d22ef3aa2f0d4bd1
linuxlinux>= eeb2d80d502af28e5660ff4bbe00f90ceb82c2db < 72222dfd76a79d9666ab3117fcdd44ca8cd0c4de72222dfd76a79d9666ab3117fcdd44ca8cd0c4de
linuxlinux>= eeb2d80d502af28e5660ff4bbe00f90ceb82c2db < d1ac288b2742aa4af746c5613bac71760fadd1c4d1ac288b2742aa4af746c5613bac71760fadd1c4
linuxlinux>= eeb2d80d502af28e5660ff4bbe00f90ceb82c2db < b7aab9d906e2e252a7783f872406033ec49b6daeb7aab9d906e2e252a7783f872406033ec49b6dae
linuxlinux>= eeb2d80d502af28e5660ff4bbe00f90ceb82c2db < 56d2eeda87995245300836ee4dbd13b00231178256d2eeda87995245300836ee4dbd13b002311782
linuxlinux_kernel>= 0 < 5.10.209-15.10.209-1
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 4.15 < 4.19.3064.19.306
linuxlinux_kernel>= 4.20 < 5.4.2685.4.268
linuxlinux_kernel>= 5.11 < 5.15.1485.15.148
linuxlinux_kernel>= 5.16 < 6.1.756.1.75
linuxlinux_kernel>= 5.5 < 5.10.2095.10.209
linuxlinux_kernel>= 6.2 < 6.6.146.6.14
linuxlinux_kernel>= 6.7 < 6.7.26.7.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.