cbcvebase.
CVE-2023-52773
published 2024-05-21

CVE-2023-52773: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix a NULL pointer dereference in amdgpu_dm_i2c_xfer() When…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.5th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix a NULL pointer dereference in amdgpu_dm_i2c_xfer() When ddc_service_construct() is called, it explicitly checks both the link type and whether there is something on the link which will dictate whether the pin is marked as hw_supported. If the pin isn't set or the link is not set (such as from unloading/reloading amdgpu in an IGT test) then fail the amdgpu_dm_i2c_xfer() call.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux>= 22676bc500c27d987a0b42cbe162aebf783f1c38 < fb5c134ca589fe670430acc9e7ebf2691ca2476dfb5c134ca589fe670430acc9e7ebf2691ca2476d
linuxlinux>= 22676bc500c27d987a0b42cbe162aebf783f1c38 < 5b14cf37b9f01de0b28c6f8960019d4c7883ce425b14cf37b9f01de0b28c6f8960019d4c7883ce42
linuxlinux>= 22676bc500c27d987a0b42cbe162aebf783f1c38 < 1d07b7e84276777dad3c8cfebdf8e739606f90c91d07b7e84276777dad3c8cfebdf8e739606f90c9
linuxlinux>= 22676bc500c27d987a0b42cbe162aebf783f1c38 < b71f4ade1b8900d30c661d6c27f87c35214c398cb71f4ade1b8900d30c661d6c27f87c35214c398c
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 6.0 < 6.1.646.1.64
linuxlinux_kernel>= 6.2 < 6.5.136.5.13
linuxlinux_kernel>= 6.6 < 6.6.36.6.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.