CVE-2023-52869
published 2024-05-21CVE-2023-52869: In the Linux kernel, the following vulnerability has been resolved: pstore/platform: Add check for kstrdup Add check for the return value of kstrdup() and…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
pstore/platform: Add check for kstrdup
Add check for the return value of kstrdup() and return the error
if it fails in order to avoid NULL pointer dereference.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.64-1 (bookworm) | linux 6.1.64-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 563ca40ddf400dbf8c6254077f9b6887101d0f08 < bb166bdae1a7d7db30e9be7e6ccaba606debc05f | bb166bdae1a7d7db30e9be7e6ccaba606debc05f |
| linux | linux | >= 563ca40ddf400dbf8c6254077f9b6887101d0f08 < 379b120e4f27fd1cf636a5f85570c4d240a3f688 | 379b120e4f27fd1cf636a5f85570c4d240a3f688 |
| linux | linux | >= 563ca40ddf400dbf8c6254077f9b6887101d0f08 < 63f637309baadf81a095f2653e3b807d4b5814b9 | 63f637309baadf81a095f2653e3b807d4b5814b9 |
| linux | linux | >= 563ca40ddf400dbf8c6254077f9b6887101d0f08 < 1c426da79f9fc7b761021b5eb44185ba119cd44a | 1c426da79f9fc7b761021b5eb44185ba119cd44a |
| linux | linux | >= 563ca40ddf400dbf8c6254077f9b6887101d0f08 < ad5cb6deb41417ef41b9d6ff54f789212108606f | ad5cb6deb41417ef41b9d6ff54f789212108606f |
| linux | linux | >= 563ca40ddf400dbf8c6254077f9b6887101d0f08 < a19d48f7c5d57c0f0405a7d4334d1d38fe9d3c1c | a19d48f7c5d57c0f0405a7d4334d1d38fe9d3c1c |
| linux | linux_kernel | >= 0 < 5.10.205-1 | 5.10.205-1 |
| linux | linux_kernel | >= 0 < 6.1.64-1 | 6.1.64-1 |
| linux | linux_kernel | >= 0 < 6.6.8-1 | 6.6.8-1 |
| linux | linux_kernel | >= 0 < 6.6.8-1 | 6.6.8-1 |
| linux | linux_kernel | >= 5.11 < 5.15.139 | 5.15.139 |
| linux | linux_kernel | >= 5.16 < 6.1.63 | 6.1.63 |
| linux | linux_kernel | >= 5.8 < 5.10.201 | 5.10.201 |
| linux | linux_kernel | >= 6.2 < 6.5.12 | 6.5.12 |
| linux | linux_kernel | >= 6.6 < 6.6.2 | 6.6.2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: pstore/platform: Add check for kstrdup
vendor_redhat·2024-05-21·CVSS 5.5
CVE-2023-52869 [MEDIUM] CWE-476 kernel: pstore/platform: Add check for kstrdup
kernel: pstore/platform: Add check for kstrdup
In the Linux kernel, the following vulnerability has been resolved:
pstore/platform: Add check for kstrdup
Add check for the return value of kstrdup() and return the error
if it fails in order to avoid NULL pointer dereference.
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 9) - Will not fix
Debian
CVE-2023-52869: linux - In the Linux kernel, the following vulnerability has been resolved: pstore/plat...
vendor_debian·2023·CVSS 5.5
CVE-2023-52869 [MEDIUM] CVE-2023-52869: linux - In the Linux kernel, the following vulnerability has been resolved: pstore/plat...
In the Linux kernel, the following vulnerability has been resolved: pstore/platform: Add check for kstrdup Add check for the return value of kstrdup() and return the error if it fails in order to avoid NULL pointer dereference.
Scope: local
bookworm: resolved (fixed in 6.1.64-1)
bullseye: resolved (fixed in 5.10.205-1)
forky: resolved (fixed in 6.6.8-1)
sid: resolved (fixed in 6.6.8-1)
trixie: resolved (fixed in 6.6.8-1)
OSV
CVE-2023-52869: In the Linux kernel, the following vulnerability has been resolved: pstore/platform: Add check for kstrdup Add check for the return value of kstrdup()
osv·2024-05-21·CVSS 5.5
CVE-2023-52869 [MEDIUM] CVE-2023-52869: In the Linux kernel, the following vulnerability has been resolved: pstore/platform: Add check for kstrdup Add check for the return value of kstrdup()
In the Linux kernel, the following vulnerability has been resolved: pstore/platform: Add check for kstrdup Add check for the return value of kstrdup() and return the error if it fails in order to avoid NULL pointer dereference.
GHSA
GHSA-xw27-hxmj-gm8p: In the Linux kernel, the following vulnerability has been resolved:
pstore/platform: Add check for kstrdup
Add check for the return value of kstrdup
ghsa_unreviewed·2024-05-21
CVE-2023-52869 [MEDIUM] CWE-476 GHSA-xw27-hxmj-gm8p: In the Linux kernel, the following vulnerability has been resolved:
pstore/platform: Add check for kstrdup
Add check for the return value of kstrdup
In the Linux kernel, the following vulnerability has been resolved:
pstore/platform: Add check for kstrdup
Add check for the return value of kstrdup() and return the error
if it fails in order to avoid NULL pointer dereference.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1c426da79f9fc7b761021b5eb44185ba119cd44ahttps://git.kernel.org/stable/c/379b120e4f27fd1cf636a5f85570c4d240a3f688https://git.kernel.org/stable/c/63f637309baadf81a095f2653e3b807d4b5814b9https://git.kernel.org/stable/c/a19d48f7c5d57c0f0405a7d4334d1d38fe9d3c1chttps://git.kernel.org/stable/c/ad5cb6deb41417ef41b9d6ff54f789212108606fhttps://git.kernel.org/stable/c/bb166bdae1a7d7db30e9be7e6ccaba606debc05fhttps://git.kernel.org/stable/c/1c426da79f9fc7b761021b5eb44185ba119cd44ahttps://git.kernel.org/stable/c/379b120e4f27fd1cf636a5f85570c4d240a3f688https://git.kernel.org/stable/c/63f637309baadf81a095f2653e3b807d4b5814b9https://git.kernel.org/stable/c/a19d48f7c5d57c0f0405a7d4334d1d38fe9d3c1chttps://git.kernel.org/stable/c/ad5cb6deb41417ef41b9d6ff54f789212108606fhttps://git.kernel.org/stable/c/bb166bdae1a7d7db30e9be7e6ccaba606debc05f
2024-05-21
Published