cbcvebase.
CVE-2023-52857
published 2024-05-21

CVE-2023-52857: In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Fix coverity issue with unintentional integer overflow 1. Instead of…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.9th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Fix coverity issue with unintentional integer overflow 1. Instead of multiplying 2 variable of different types. Change to assign a value of one variable and then multiply the other variable. 2. Add a int variable for multiplier calculation instead of calculating different types multiplier with dma_addr_t variable directly.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 1a64a7aff8da352c9419de3d5c34343682916411 < a12bd675100531f9fb4508fd4430dd1632325a0ea12bd675100531f9fb4508fd4430dd1632325a0e
linuxlinux>= 1a64a7aff8da352c9419de3d5c34343682916411 < 0d8a1df39d3fc34560e2cc663b5c340d06a253960d8a1df39d3fc34560e2cc663b5c340d06a25396
linuxlinux>= 1a64a7aff8da352c9419de3d5c34343682916411 < 96312a251d4dcee5d36e32edba3002bfde0ddd9c96312a251d4dcee5d36e32edba3002bfde0ddd9c
linuxlinux>= 1a64a7aff8da352c9419de3d5c34343682916411 < b0b0d811eac6b4c52cb9ad632fa6384cf48869e7b0b0d811eac6b4c52cb9ad632fa6384cf48869e7
linuxlinux>= 5.13.12 < 5.145.14
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 5.13.12 < 6.5.126.5.12
linuxlinux_kernel>= 6.6 < 6.6.26.6.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.