cbcvebase.
CVE-2023-52817
published 2024-05-21

CVE-2023-52817: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix a null pointer access when the smc_rreg pointer is NULL In certain types of…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.2th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix a null pointer access when the smc_rreg pointer is NULL In certain types of chips, such as VEGA20, reading the amdgpu_regs_smc file could result in an abnormal null pointer access when the smc_rreg pointer is NULL. Below are the steps to reproduce this issue and the corresponding exception log: 1. Navigate to the directory: /sys/kernel/debug/dri/0 2. Execute command: cat amdgpu_regs_smc 3. Exception Log:: [4005007.702554] BUG: kernel NULL pointer dereference, address: 0000000000000000 [4005007.702562] #PF: supervisor instruction fetch in kernel mode [4005007.702567] #PF: error_code(0x0010) - not-present page [4005007.702570] PGD 0 P4D 0 [4005007.702576] Oops: 0010 [#1] SMP NOPTI [4005007.702581] CPU: 4 PID: 62563 Comm: cat Tainted: G OE 5.15.0-43-generic #46-Ubunt u [4005007.702590] RIP: 0010:0x0 [4005007.702598] Code: Unable to access opcode bytes at RIP 0xffffffffffffffd6. [4005007.702600] RSP: 0018:ffffa82b46d27da0 EFLAGS: 00010206 [4005007.702605] RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffffa82b46d27e68 [4005007.702609] RDX: 0000000000000001 RSI: 0000000000000000 RDI: ffff9940656e0000 [4005007.702612] RBP: ffffa82b46d27dd8 R08: 0000000000000000 R09: ffff994060c07980 [4005007.702615] R10: 0000000000020000 R11: 0000000000000000 R12: 00007f5e06753000 [4005007.702618] R13: ffff9940656e0000 R14: ffffa82b46d27e68 R15: 00007f5e06753000 [4005007.702622] FS: 00007f5e0755b740(0000) GS:ffff99479d300000(0000) knlGS:0000000000000000 [4005007.702626] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [4005007.702629] CR2: ffffffffffffffd6 CR3: 00000003253fc000 CR4: 00000000003506e0 [4005007.702633] Call Trace: [4005007.702636] [4005007.702640] amdgpu_debugfs_regs_smc_read+0xb0/0x120 [amdgpu] [4005007.703002] full_proxy_read+0x5c/0x80 [4005007.703011] vfs_read+0x9f/0x1a0 [4005007.703019] ksys_read+0x67/0xe0 [4005007.703023] __x64_sys_read+0x19/0x20 [4005007.703028] do_syscall_64+0x5c/

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < bf2d51eedf03bd61e3556e35d74d49e2e6112398bf2d51eedf03bd61e3556e35d74d49e2e6112398
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < 437e0fa907ba39b4d7eda863c03ea9cf48bd93a9437e0fa907ba39b4d7eda863c03ea9cf48bd93a9
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < f475d5502f33a6c5b149b0afe96316ad1962a64af475d5502f33a6c5b149b0afe96316ad1962a64a
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < 174f62a0aa15c211e60208b41ee9e7cdfb73d455174f62a0aa15c211e60208b41ee9e7cdfb73d455
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < 6c1b3d89a2dda79881726bb6e37af19c0936d7366c1b3d89a2dda79881726bb6e37af19c0936d736
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < 820daf9ffe2b0afb804567b10983fb38bc5ae288820daf9ffe2b0afb804567b10983fb38bc5ae288
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < ba3c0796d292de84f2932cc5bbb0f771fc720996ba3c0796d292de84f2932cc5bbb0f771fc720996
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < 5104fdf50d326db2c1a994f8b35dcd46e63ae4ad5104fdf50d326db2c1a994f8b35dcd46e63ae4ad
linuxlinux_kernel< 4.19.3004.19.300
linuxlinux_kernel>= 0 < 5.10.205-15.10.205-1
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 4.20 < 5.4.2625.4.262
linuxlinux_kernel>= 5.11 < 5.15.1405.15.140
linuxlinux_kernel>= 5.16 < 6.1.646.1.64
linuxlinux_kernel>= 5.5 < 5.10.2025.10.202
linuxlinux_kernel>= 6.2 < 6.5.136.5.13
linuxlinux_kernel>= 6.6 < 6.6.36.6.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.