cbcvebase.
CVE-2023-52789
published 2024-05-21

CVE-2023-52789: In the Linux kernel, the following vulnerability has been resolved: tty: vcc: Add check for kstrdup() in vcc_probe() Add check for the return value of…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
15.9th percentile
In the Linux kernel, the following vulnerability has been resolved: tty: vcc: Add check for kstrdup() in vcc_probe() Add check for the return value of kstrdup() and return the error, if it fails in order to avoid NULL pointer dereference.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux>= 5d171050e28f823aeb040f2830da4d3422b54b63 < 38cd56fc9de78bf3c878790785e8c231116ef9d338cd56fc9de78bf3c878790785e8c231116ef9d3
linuxlinux>= 5d171050e28f823aeb040f2830da4d3422b54b63 < 909963e0c16778cec28efb1affc21558825f4200909963e0c16778cec28efb1affc21558825f4200
linuxlinux>= 5d171050e28f823aeb040f2830da4d3422b54b63 < 460284dfb10b207980c6f3f7046e33446ceb38ac460284dfb10b207980c6f3f7046e33446ceb38ac
linuxlinux>= 5d171050e28f823aeb040f2830da4d3422b54b63 < 4ef41a7f33ffe1a335e7db7e1564ddc6afad47cc4ef41a7f33ffe1a335e7db7e1564ddc6afad47cc
linuxlinux>= 5d171050e28f823aeb040f2830da4d3422b54b63 < 6c80f48912b5bd4965352d1a9a989e21743a4a066c80f48912b5bd4965352d1a9a989e21743a4a06
linuxlinux>= 5d171050e28f823aeb040f2830da4d3422b54b63 < 7cebc86481bf16049e266f6774d90f2fd4f8d5d27cebc86481bf16049e266f6774d90f2fd4f8d5d2
linuxlinux>= 5d171050e28f823aeb040f2830da4d3422b54b63 < 4a24a31826246b15477399febd13292b0c9f0ee94a24a31826246b15477399febd13292b0c9f0ee9
linuxlinux>= 5d171050e28f823aeb040f2830da4d3422b54b63 < 8f8771757b130383732195497e47fba2aba76d3a8f8771757b130383732195497e47fba2aba76d3a
linuxlinux>= 5d171050e28f823aeb040f2830da4d3422b54b63 < d81ffb87aaa75f842cd7aa57091810353755b3e6d81ffb87aaa75f842cd7aa57091810353755b3e6
linuxlinux_kernel< 4.14.3314.14.331
linuxlinux_kernel>= 0 < 5.10.205-15.10.205-1
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 4.15 < 4.19.3004.19.300
linuxlinux_kernel>= 4.20 < 5.4.2625.4.262
linuxlinux_kernel>= 5.11 < 5.15.1405.15.140
linuxlinux_kernel>= 5.16 < 6.1.646.1.64
linuxlinux_kernel>= 5.5 < 5.10.2025.10.202
linuxlinux_kernel>= 6.2 < 6.5.136.5.13
linuxlinux_kernel>= 6.6 < 6.6.36.6.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.