cbcvebase.
CVE-2023-52690
published 2024-05-17

CVE-2023-52690: In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv: Add a null pointer check to scom_debug_init_one() kasprintf() returns a…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.3th percentile
In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv: Add a null pointer check to scom_debug_init_one() kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure. Add a null pointer check, and release 'ent' to avoid memory leaks.

Affected

20 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux
linuxlinux>= bfd2f0d49aef8abfe6bf58f12719f39912993cc6 < f84c1446daa552e9699da8d1f8375eac0f65edc7f84c1446daa552e9699da8d1f8375eac0f65edc7
linuxlinux>= bfd2f0d49aef8abfe6bf58f12719f39912993cc6 < 1eefa93faf69188540b08b024794fa90b1d82e8b1eefa93faf69188540b08b024794fa90b1d82e8b
linuxlinux>= bfd2f0d49aef8abfe6bf58f12719f39912993cc6 < 2a82c4439b903639e0a1f21990cd399fb0a49c192a82c4439b903639e0a1f21990cd399fb0a49c19
linuxlinux>= bfd2f0d49aef8abfe6bf58f12719f39912993cc6 < ed8d023cfa97b559db58c0e1afdd2eec7a83d8f2ed8d023cfa97b559db58c0e1afdd2eec7a83d8f2
linuxlinux>= bfd2f0d49aef8abfe6bf58f12719f39912993cc6 < dd8422ff271c22058560832fc3006324ded895a9dd8422ff271c22058560832fc3006324ded895a9
linuxlinux>= bfd2f0d49aef8abfe6bf58f12719f39912993cc6 < a9c05cbb6644a2103c75b6906e9dafb9981ebd13a9c05cbb6644a2103c75b6906e9dafb9981ebd13
linuxlinux>= bfd2f0d49aef8abfe6bf58f12719f39912993cc6 < 9a260f2dd827bbc82cc60eb4f4d8c22707d807429a260f2dd827bbc82cc60eb4f4d8c22707d80742
linuxlinux_kernel>= 0 < 5.10.209-15.10.209-1
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 5.11 < 5.15.1485.15.148
linuxlinux_kernel>= 5.16 < 6.1.756.1.75
linuxlinux_kernel>= 5.4 < 5.4.2685.4.268
linuxlinux_kernel>= 5.5 < 5.10.2095.10.209
linuxlinux_kernel>= 6.2 < 6.6.146.6.14
linuxlinux_kernel>= 6.7 < 6.7.26.7.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.