cbcvebase.
CVE-2023-52861
published 2024-05-21

CVE-2023-52861: In the Linux kernel, the following vulnerability has been resolved: drm: bridge: it66121: Fix invalid connector dereference Fix the NULL pointer dereference…

PriorityP420medium6.2CVSS 3.1
AVLACLPRNUINSUCNINAH
EPSS
0.25%
16.2th percentile
In the Linux kernel, the following vulnerability has been resolved: drm: bridge: it66121: Fix invalid connector dereference Fix the NULL pointer dereference when no monitor is connected, and the sound card is opened from userspace. Instead return an empty buffer (of zeroes) as the EDID information to the sound framework if there is no connector attached.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux>= e0fd83dbe92426e4f09b01111d260d2a7dc72fdb < 2c80c4f0d2845645f41cbb7c9304c8efbdbd43312c80c4f0d2845645f41cbb7c9304c8efbdbd4331
linuxlinux>= e0fd83dbe92426e4f09b01111d260d2a7dc72fdb < 1669d7b21a664aa531856ce85b01359a376baebc1669d7b21a664aa531856ce85b01359a376baebc
linuxlinux>= e0fd83dbe92426e4f09b01111d260d2a7dc72fdb < 1374561a7cbc9a000b77bb0473bb2c19daf18d861374561a7cbc9a000b77bb0473bb2c19daf18d86
linuxlinux>= e0fd83dbe92426e4f09b01111d260d2a7dc72fdb < d0375f6858c4ff7244b62b02eb5e93428e1916cdd0375f6858c4ff7244b62b02eb5e93428e1916cd
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 5.19 < 6.1.636.1.63
linuxlinux_kernel>= 6.2 < 6.5.126.5.12
linuxlinux_kernel>= 6.6 < 6.6.26.6.2

CVSS provenance

nvdv3.16.2MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv6.2MEDIUM
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.