CVE-2023-52871
published 2024-05-21CVE-2023-52871: In the Linux kernel, the following vulnerability has been resolved: soc: qcom: llcc: Handle a second device without data corruption Usually there is only one…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
EPSS
0.22%
13.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
soc: qcom: llcc: Handle a second device without data corruption
Usually there is only one llcc device. But if there were a second, even
a failed probe call would modify the global drv_data pointer. So check
if drv_data is valid before overwriting it.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.64-1 (bookworm) | linux 6.1.64-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= a3134fb09e0bc5bee76e13bf863173b86f21cf87 < cc1a1dcb411fe224f48553cfdcdfe6e61395b69c | cc1a1dcb411fe224f48553cfdcdfe6e61395b69c |
| linux | linux | >= a3134fb09e0bc5bee76e13bf863173b86f21cf87 < 5e5b85ea0f4bc484bfe4cc73ead51fa48d2366a0 | 5e5b85ea0f4bc484bfe4cc73ead51fa48d2366a0 |
| linux | linux | >= a3134fb09e0bc5bee76e13bf863173b86f21cf87 < 995ee1e84e8db7fa5dcdde7dfe0bd7bb6f9bbb8c | 995ee1e84e8db7fa5dcdde7dfe0bd7bb6f9bbb8c |
| linux | linux | >= a3134fb09e0bc5bee76e13bf863173b86f21cf87 < f0ef883cae309bc5e8cdfcdbc1b4822732ce20a8 | f0ef883cae309bc5e8cdfcdbc1b4822732ce20a8 |
| linux | linux | >= a3134fb09e0bc5bee76e13bf863173b86f21cf87 < 3565684309e54fa998ea27f37028d67cc3e1dff2 | 3565684309e54fa998ea27f37028d67cc3e1dff2 |
| linux | linux | >= a3134fb09e0bc5bee76e13bf863173b86f21cf87 < 1143bfb9b055897975aeaea254da148e19524493 | 1143bfb9b055897975aeaea254da148e19524493 |
| linux | linux | >= a3134fb09e0bc5bee76e13bf863173b86f21cf87 < f1a1bc8775b26345aba2be278118999e7f661d3d | f1a1bc8775b26345aba2be278118999e7f661d3d |
| linux | linux_kernel | >= 0 < 5.10.205-1 | 5.10.205-1 |
| linux | linux_kernel | >= 0 < 6.1.64-1 | 6.1.64-1 |
| linux | linux_kernel | >= 0 < 6.6.8-1 | 6.6.8-1 |
| linux | linux_kernel | >= 0 < 6.6.8-1 | 6.6.8-1 |
| linux | linux_kernel | >= 4.19 < 5.4.261 | 5.4.261 |
| linux | linux_kernel | >= 5.11 < 5.15.139 | 5.15.139 |
| linux | linux_kernel | >= 5.16 < 6.1.63 | 6.1.63 |
| linux | linux_kernel | >= 5.5 < 5.10.201 | 5.10.201 |
| linux | linux_kernel | >= 6.2 < 6.5.12 | 6.5.12 |
| linux | linux_kernel | >= 6.6 < 6.6.2 | 6.6.2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w492-g7j4-gr3w: In the Linux kernel, the following vulnerability has been resolved:
soc: qcom: llcc: Handle a second device without data corruption
Usually there is
ghsa_unreviewed·2024-05-21
CVE-2023-52871 [MEDIUM] GHSA-w492-g7j4-gr3w: In the Linux kernel, the following vulnerability has been resolved:
soc: qcom: llcc: Handle a second device without data corruption
Usually there is
In the Linux kernel, the following vulnerability has been resolved:
soc: qcom: llcc: Handle a second device without data corruption
Usually there is only one llcc device. But if there were a second, even
a failed probe call would modify the global drv_data pointer. So check
if drv_data is valid before overwriting it.
OSV
CVE-2023-52871: In the Linux kernel, the following vulnerability has been resolved: soc: qcom: llcc: Handle a second device without data corruption Usually there is o
osv·2024-05-21·CVSS 5.5
CVE-2023-52871 [MEDIUM] CVE-2023-52871: In the Linux kernel, the following vulnerability has been resolved: soc: qcom: llcc: Handle a second device without data corruption Usually there is o
In the Linux kernel, the following vulnerability has been resolved: soc: qcom: llcc: Handle a second device without data corruption Usually there is only one llcc device. But if there were a second, even a failed probe call would modify the global drv_data pointer. So check if drv_data is valid before overwriting it.
CISA ICS
Siemens SINEC OS
cisa_ics·2025-08-14
Siemens SINEC OS
ICS Advisory
##
Siemens SINEC OS
Release DateAugust 14, 2025
Alert CodeICSA-25-226-15
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3.1 9.1
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: RUGGEDCOM, SCALANCE
- Vulnerabilities: NULL Pointer Dereference, Use After Free, Unchecked Input for Loop Condition, Out-of-bounds Write, Ou
Red Hat
kernel: soc: qcom: llcc: Handle a second device without data corruption
vendor_redhat·2024-05-21·CVSS 5.5
CVE-2023-52871 [MEDIUM] CWE-99 kernel: soc: qcom: llcc: Handle a second device without data corruption
kernel: soc: qcom: llcc: Handle a second device without data corruption
In the Linux kernel, the following vulnerability has been resolved:
soc: qcom: llcc: Handle a second device without data corruption
Usually there is only one llcc device. But if there were a second, even
a failed probe call would modify the global drv_data pointer. So check
if drv_data is valid before overwriting it.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - Not affected
Package: kernel-rt (Red Hat Enterpr
Debian
CVE-2023-52871: linux - In the Linux kernel, the following vulnerability has been resolved: soc: qcom: ...
vendor_debian·2023·CVSS 5.5
CVE-2023-52871 [MEDIUM] CVE-2023-52871: linux - In the Linux kernel, the following vulnerability has been resolved: soc: qcom: ...
In the Linux kernel, the following vulnerability has been resolved: soc: qcom: llcc: Handle a second device without data corruption Usually there is only one llcc device. But if there were a second, even a failed probe call would modify the global drv_data pointer. So check if drv_data is valid before overwriting it.
Scope: local
bookworm: resolved (fixed in 6.1.64-1)
bullseye: resolved (fixed in 5.10.205-1)
forky: resolved (fixed in 6.6.8-1)
sid: resolved (fixed in 6.6.8-1)
trixie: resolved (fixed in 6.6.8-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1143bfb9b055897975aeaea254da148e19524493https://git.kernel.org/stable/c/3565684309e54fa998ea27f37028d67cc3e1dff2https://git.kernel.org/stable/c/5e5b85ea0f4bc484bfe4cc73ead51fa48d2366a0https://git.kernel.org/stable/c/995ee1e84e8db7fa5dcdde7dfe0bd7bb6f9bbb8chttps://git.kernel.org/stable/c/cc1a1dcb411fe224f48553cfdcdfe6e61395b69chttps://git.kernel.org/stable/c/f0ef883cae309bc5e8cdfcdbc1b4822732ce20a8https://git.kernel.org/stable/c/f1a1bc8775b26345aba2be278118999e7f661d3dhttps://git.kernel.org/stable/c/1143bfb9b055897975aeaea254da148e19524493https://git.kernel.org/stable/c/3565684309e54fa998ea27f37028d67cc3e1dff2https://git.kernel.org/stable/c/5e5b85ea0f4bc484bfe4cc73ead51fa48d2366a0https://git.kernel.org/stable/c/995ee1e84e8db7fa5dcdde7dfe0bd7bb6f9bbb8chttps://git.kernel.org/stable/c/cc1a1dcb411fe224f48553cfdcdfe6e61395b69chttps://git.kernel.org/stable/c/f0ef883cae309bc5e8cdfcdbc1b4822732ce20a8https://git.kernel.org/stable/c/f1a1bc8775b26345aba2be278118999e7f661d3d
2024-05-21
Published