cbcvebase.
CVE-2023-52693
published 2024-05-17

CVE-2023-52693: In the Linux kernel, the following vulnerability has been resolved: ACPI: video: check for error while searching for backlight device parent If…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.0th percentile
In the Linux kernel, the following vulnerability has been resolved: ACPI: video: check for error while searching for backlight device parent If acpi_get_parent() called in acpi_video_dev_register_backlight() fails, for example, because acpi_ut_acquire_mutex() fails inside acpi_get_parent), this can lead to incorrect (uninitialized) acpi_parent handle being passed to acpi_get_pci_dev() for detecting the parent pci device. Check acpi_get_parent() result and set parent device only in case of success. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected

22 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux
linuxlinux>= 9661e92c10a9775243c1ecb73373528ed8725a10 < 556f02699d33c1f40b1b31bd25828ce08fa165d8556f02699d33c1f40b1b31bd25828ce08fa165d8
linuxlinux>= 9661e92c10a9775243c1ecb73373528ed8725a10 < 1e3a2b9b4039bb4d136dca59fb31e06465e056f31e3a2b9b4039bb4d136dca59fb31e06465e056f3
linuxlinux>= 9661e92c10a9775243c1ecb73373528ed8725a10 < c4e1a0ef0b4782854c9b77a333ca912b392bed2fc4e1a0ef0b4782854c9b77a333ca912b392bed2f
linuxlinux>= 9661e92c10a9775243c1ecb73373528ed8725a10 < 3a370502a5681986f9828e43be75ce26c6ab24af3a370502a5681986f9828e43be75ce26c6ab24af
linuxlinux>= 9661e92c10a9775243c1ecb73373528ed8725a10 < 2124c5bc22948fc4d09a23db4a8acdccc7d21e952124c5bc22948fc4d09a23db4a8acdccc7d21e95
linuxlinux>= 9661e92c10a9775243c1ecb73373528ed8725a10 < 39af144b6d01d9b40f52e5d773e653957e6c379c39af144b6d01d9b40f52e5d773e653957e6c379c
linuxlinux>= 9661e92c10a9775243c1ecb73373528ed8725a10 < 72884ce4e10417b1233b614bf134da852df0f15f72884ce4e10417b1233b614bf134da852df0f15f
linuxlinux>= 9661e92c10a9775243c1ecb73373528ed8725a10 < ccd45faf4973746c4f30ea41eec864e5cf191099ccd45faf4973746c4f30ea41eec864e5cf191099
linuxlinux_kernel>= 0 < 5.10.209-15.10.209-1
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 2.6.39 < 4.19.3064.19.306
linuxlinux_kernel>= 4.20 < 5.4.2685.4.268
linuxlinux_kernel>= 5.11 < 5.15.1485.15.148
linuxlinux_kernel>= 5.16 < 6.1.756.1.75
linuxlinux_kernel>= 5.5 < 5.10.2095.10.209
linuxlinux_kernel>= 6.2 < 6.6.146.6.14
linuxlinux_kernel>= 6.7 < 6.7.26.7.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.