cbcvebase.
CVE-2023-52788
published 2024-05-21

CVE-2023-52788: In the Linux kernel, the following vulnerability has been resolved: i915/perf: Fix NULL deref bugs with drm_dbg() calls When i915 perf interface is not…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.6th percentile
In the Linux kernel, the following vulnerability has been resolved: i915/perf: Fix NULL deref bugs with drm_dbg() calls When i915 perf interface is not available dereferencing it will lead to NULL dereferences. As returning -ENOTSUPP is pretty clear return when perf interface is not available. [tursulin: added stable tag] (cherry picked from commit 36f27350ff745bd228ab04d7845dfbffc177a889)

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux>= 2fec539112e89255b6a47f566e21d99937fada7b < 55db76caa782baa4a1bf02296e2773c38a524a3e55db76caa782baa4a1bf02296e2773c38a524a3e
linuxlinux>= 2fec539112e89255b6a47f566e21d99937fada7b < bf8e105030083e7b71591cdf437e464bcd8a0c09bf8e105030083e7b71591cdf437e464bcd8a0c09
linuxlinux>= 2fec539112e89255b6a47f566e21d99937fada7b < 10f49cdfd5fb342a1a9641930dc040c570694e9810f49cdfd5fb342a1a9641930dc040c570694e98
linuxlinux>= 2fec539112e89255b6a47f566e21d99937fada7b < 471aa951bf1206d3c10d0daa67005b8e4db4ff83471aa951bf1206d3c10d0daa67005b8e4db4ff83
linuxlinux>= 5.15.108 < 5.15.1405.15.140
linuxlinux>= 9b344cf6aea0a69c00e19efdc6e02c6d5aae1a23 < 1566e8be73fd5fa424e88d2a4cffdc34f970f0e11566e8be73fd5fa424e88d2a4cffdc34f970f0e1
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 5.15.108 < 5.15.1405.15.140
linuxlinux_kernel>= 6.0 < 6.1.646.1.64
linuxlinux_kernel>= 6.2 < 6.5.136.5.13
linuxlinux_kernel>= 6.6 < 6.6.36.6.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.