CVE-2023-52864
published 2024-05-21CVE-2023-52864: In the Linux kernel, the following vulnerability has been resolved: platform/x86: wmi: Fix opening of char device Since commit fa1f68db6ca7 ("drivers: misc…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
18.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: wmi: Fix opening of char device
Since commit fa1f68db6ca7 ("drivers: misc: pass miscdevice pointer via
file private data"), the miscdevice stores a pointer to itself inside
filp->private_data, which means that private_data will not be NULL when
wmi_char_open() is called. This might cause memory corruption should
wmi_char_open() be unable to find its driver, something which can
happen when the associated WMI device is deleted in wmi_free_devices().
Fix the problem by using the miscdevice pointer to retrieve the WMI
device data associated with a char device using container_of(). This
also avoids wmi_char_open() picking a wrong WMI device bound to a
driver with the same name as the original driver.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.64-1 (bookworm) | linux 6.1.64-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 44b6b7661132b1b0e5fd3147ded66f1e4a817ca9 < cf098e937dd125c0317a0d6f261ac2a950a233d6 | cf098e937dd125c0317a0d6f261ac2a950a233d6 |
| linux | linux | >= 44b6b7661132b1b0e5fd3147ded66f1e4a817ca9 < 9fb0eed09e1470cd4021ff52b2b9dfcbcee4c203 | 9fb0eed09e1470cd4021ff52b2b9dfcbcee4c203 |
| linux | linux | >= 44b6b7661132b1b0e5fd3147ded66f1e4a817ca9 < d426a2955e45a95b2282764105fcfb110a540453 | d426a2955e45a95b2282764105fcfb110a540453 |
| linux | linux | >= 44b6b7661132b1b0e5fd3147ded66f1e4a817ca9 < e0bf076b734a2fab92d8fddc2b8b03462eee7097 | e0bf076b734a2fab92d8fddc2b8b03462eee7097 |
| linux | linux | >= 44b6b7661132b1b0e5fd3147ded66f1e4a817ca9 < 44a96796d25809502c75771d40ee693c2e44724e | 44a96796d25809502c75771d40ee693c2e44724e |
| linux | linux | >= 44b6b7661132b1b0e5fd3147ded66f1e4a817ca9 < 36d85fa7ae0d6be651c1a745191fa7ef055db43e | 36d85fa7ae0d6be651c1a745191fa7ef055db43e |
| linux | linux | >= 44b6b7661132b1b0e5fd3147ded66f1e4a817ca9 < fb7b06b59c6887659c6ed0ecd3110835eecbb6a3 | fb7b06b59c6887659c6ed0ecd3110835eecbb6a3 |
| linux | linux | >= 44b6b7661132b1b0e5fd3147ded66f1e4a817ca9 < eba9ac7abab91c8f6d351460239108bef5e7a0b6 | eba9ac7abab91c8f6d351460239108bef5e7a0b6 |
| linux | linux_kernel | >= 0 < 5.10.205-1 | 5.10.205-1 |
| linux | linux_kernel | >= 0 < 6.1.64-1 | 6.1.64-1 |
| linux | linux_kernel | >= 0 < 6.6.8-1 | 6.6.8-1 |
| linux | linux_kernel | >= 0 < 6.6.8-1 | 6.6.8-1 |
| linux | linux_kernel | >= 4.15 < 4.19.299 | 4.19.299 |
| linux | linux_kernel | >= 4.20 < 5.4.261 | 5.4.261 |
| linux | linux_kernel | >= 5.11 < 5.15.139 | 5.15.139 |
| linux | linux_kernel | >= 5.16 < 6.1.63 | 6.1.63 |
| linux | linux_kernel | >= 5.5 < 5.10.201 | 5.10.201 |
| linux | linux_kernel | >= 6.2 < 6.5.12 | 6.5.12 |
| linux | linux_kernel | >= 6.6 < 6.6.2 | 6.6.2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SINEC OS
cisa_ics·2025-08-14
Siemens SINEC OS
ICS Advisory
##
Siemens SINEC OS
Release DateAugust 14, 2025
Alert CodeICSA-25-226-15
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3.1 9.1
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: RUGGEDCOM, SCALANCE
- Vulnerabilities: NULL Pointer Dereference, Use After Free, Unchecked Input for Loop Condition, Out-of-bounds Write, Ou
Red Hat
kernel: platform/x86: wmi: Fix opening of char device
vendor_redhat·2024-05-21·CVSS 7.8
CVE-2023-52864 [HIGH] CWE-402 kernel: platform/x86: wmi: Fix opening of char device
kernel: platform/x86: wmi: Fix opening of char device
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: wmi: Fix opening of char device
Since commit fa1f68db6ca7 ("drivers: misc: pass miscdevice pointer via
file private data"), the miscdevice stores a pointer to itself inside
filp->private_data, which means that private_data will not be NULL when
wmi_char_open() is called. This might cause memory corruption should
wmi_char_open() be unable to find its driver, something which can
happen when the associated WMI device is deleted in wmi_free_devices().
Fix the problem by using the miscdevice pointer to retrieve the WMI
device data associated with a char device using container_of(). This
also avoids wmi_char_open() picking a wrong WMI device bound to a
driver w
Debian
CVE-2023-52864: linux - In the Linux kernel, the following vulnerability has been resolved: platform/x8...
vendor_debian·2023·CVSS 7.8
CVE-2023-52864 [HIGH] CVE-2023-52864: linux - In the Linux kernel, the following vulnerability has been resolved: platform/x8...
In the Linux kernel, the following vulnerability has been resolved: platform/x86: wmi: Fix opening of char device Since commit fa1f68db6ca7 ("drivers: misc: pass miscdevice pointer via file private data"), the miscdevice stores a pointer to itself inside filp->private_data, which means that private_data will not be NULL when wmi_char_open() is called. This might cause memory corruption should wmi_char_open() be unable to find its driver, something which can happen when the associated WMI device is deleted in wmi_free_devices(). Fix the problem by using the miscdevice pointer to retrieve the WMI device data associated with a char device using container_of(). This also avoids wmi_char_open() picking a wrong WMI device bound to a driver with the same name as the original driver.
Scope: local
OSV
CVE-2023-52864: In the Linux kernel, the following vulnerability has been resolved: platform/x86: wmi: Fix opening of char device Since commit fa1f68db6ca7 ("drivers:
osv·2024-05-21·CVSS 7.8
CVE-2023-52864 [HIGH] CVE-2023-52864: In the Linux kernel, the following vulnerability has been resolved: platform/x86: wmi: Fix opening of char device Since commit fa1f68db6ca7 ("drivers:
In the Linux kernel, the following vulnerability has been resolved: platform/x86: wmi: Fix opening of char device Since commit fa1f68db6ca7 ("drivers: misc: pass miscdevice pointer via file private data"), the miscdevice stores a pointer to itself inside filp->private_data, which means that private_data will not be NULL when wmi_char_open() is called. This might cause memory corruption should wmi_char_open() be unable to find its driver, something which can happen when the associated WMI device is deleted in wmi_free_devices(). Fix the problem by using the miscdevice pointer to retrieve the WMI device data associated with a char device using container_of(). This also avoids wmi_char_open() picking a wrong WMI device bound to a driver with the same name as the original driver.
GHSA
GHSA-w33v-fh8v-9mhx: In the Linux kernel, the following vulnerability has been resolved:
platform/x86: wmi: Fix opening of char device
Since commit fa1f68db6ca7 ("driver
ghsa_unreviewed·2024-05-21
CVE-2023-52864 [HIGH] CWE-787 GHSA-w33v-fh8v-9mhx: In the Linux kernel, the following vulnerability has been resolved:
platform/x86: wmi: Fix opening of char device
Since commit fa1f68db6ca7 ("driver
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: wmi: Fix opening of char device
Since commit fa1f68db6ca7 ("drivers: misc: pass miscdevice pointer via
file private data"), the miscdevice stores a pointer to itself inside
filp->private_data, which means that private_data will not be NULL when
wmi_char_open() is called. This might cause memory corruption should
wmi_char_open() be unable to find its driver, something which can
happen when the associated WMI device is deleted in wmi_free_devices().
Fix the problem by using the miscdevice pointer to retrieve the WMI
device data associated with a char device using container_of(). This
also avoids wmi_char_open() picking a wrong WMI device bound to a
driver with the same name as the original driver.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/36d85fa7ae0d6be651c1a745191fa7ef055db43ehttps://git.kernel.org/stable/c/44a96796d25809502c75771d40ee693c2e44724ehttps://git.kernel.org/stable/c/9fb0eed09e1470cd4021ff52b2b9dfcbcee4c203https://git.kernel.org/stable/c/cf098e937dd125c0317a0d6f261ac2a950a233d6https://git.kernel.org/stable/c/d426a2955e45a95b2282764105fcfb110a540453https://git.kernel.org/stable/c/e0bf076b734a2fab92d8fddc2b8b03462eee7097https://git.kernel.org/stable/c/eba9ac7abab91c8f6d351460239108bef5e7a0b6https://git.kernel.org/stable/c/fb7b06b59c6887659c6ed0ecd3110835eecbb6a3https://git.kernel.org/stable/c/36d85fa7ae0d6be651c1a745191fa7ef055db43ehttps://git.kernel.org/stable/c/44a96796d25809502c75771d40ee693c2e44724ehttps://git.kernel.org/stable/c/9fb0eed09e1470cd4021ff52b2b9dfcbcee4c203https://git.kernel.org/stable/c/cf098e937dd125c0317a0d6f261ac2a950a233d6https://git.kernel.org/stable/c/d426a2955e45a95b2282764105fcfb110a540453https://git.kernel.org/stable/c/e0bf076b734a2fab92d8fddc2b8b03462eee7097https://git.kernel.org/stable/c/eba9ac7abab91c8f6d351460239108bef5e7a0b6https://git.kernel.org/stable/c/fb7b06b59c6887659c6ed0ecd3110835eecbb6a3
2024-05-21
Published