cbcvebase.
CVE-2023-52869
published 2024-05-21

CVE-2023-52869: In the Linux kernel, the following vulnerability has been resolved: pstore/platform: Add check for kstrdup Add check for the return value of kstrdup() and…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.0th percentile
In the Linux kernel, the following vulnerability has been resolved: pstore/platform: Add check for kstrdup Add check for the return value of kstrdup() and return the error if it fails in order to avoid NULL pointer dereference.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux>= 563ca40ddf400dbf8c6254077f9b6887101d0f08 < bb166bdae1a7d7db30e9be7e6ccaba606debc05fbb166bdae1a7d7db30e9be7e6ccaba606debc05f
linuxlinux>= 563ca40ddf400dbf8c6254077f9b6887101d0f08 < 379b120e4f27fd1cf636a5f85570c4d240a3f688379b120e4f27fd1cf636a5f85570c4d240a3f688
linuxlinux>= 563ca40ddf400dbf8c6254077f9b6887101d0f08 < 63f637309baadf81a095f2653e3b807d4b5814b963f637309baadf81a095f2653e3b807d4b5814b9
linuxlinux>= 563ca40ddf400dbf8c6254077f9b6887101d0f08 < 1c426da79f9fc7b761021b5eb44185ba119cd44a1c426da79f9fc7b761021b5eb44185ba119cd44a
linuxlinux>= 563ca40ddf400dbf8c6254077f9b6887101d0f08 < ad5cb6deb41417ef41b9d6ff54f789212108606fad5cb6deb41417ef41b9d6ff54f789212108606f
linuxlinux>= 563ca40ddf400dbf8c6254077f9b6887101d0f08 < a19d48f7c5d57c0f0405a7d4334d1d38fe9d3c1ca19d48f7c5d57c0f0405a7d4334d1d38fe9d3c1c
linuxlinux_kernel>= 0 < 5.10.205-15.10.205-1
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 5.11 < 5.15.1395.15.139
linuxlinux_kernel>= 5.16 < 6.1.636.1.63
linuxlinux_kernel>= 5.8 < 5.10.2015.10.201
linuxlinux_kernel>= 6.2 < 6.5.126.5.12
linuxlinux_kernel>= 6.6 < 6.6.26.6.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.