CVE-2023-52915
published 2024-09-06CVE-2023-52915: In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb-v2: af9035: Fix null-ptr-deref in af9035_i2c_master_xfer In…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
media: dvb-usb-v2: af9035: Fix null-ptr-deref in af9035_i2c_master_xfer
In af9035_i2c_master_xfer, msg is controlled by user. When msg[i].buf
is null and msg[i].len is zero, former checks on msg[i].buf would be
passed. Malicious data finally reach af9035_i2c_master_xfer. If accessing
msg[i].buf[0] without sanity check, null ptr deref would happen.
We add check on msg[i].len to prevent crash.
Similar commit:
commit 0ed554fd769a
("media: dvb-usb: az6027: fix null-ptr-deref in az6027_i2c_xfer()")
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.55-1 (bookworm) | linux 6.1.55-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 7f882c2e353ca58695e9b4fcc9e97a9d4cbcf273 < b2f54ed7739dfdf42c4df0a11131aad7c8635464 | b2f54ed7739dfdf42c4df0a11131aad7c8635464 |
| linux | linux | >= 7f882c2e353ca58695e9b4fcc9e97a9d4cbcf273 < fa58d9db5cad4bb7bb694b6837e3b96d87554f2b | fa58d9db5cad4bb7bb694b6837e3b96d87554f2b |
| linux | linux | >= 7f882c2e353ca58695e9b4fcc9e97a9d4cbcf273 < b49c6e5dd236787f13a062ec528d724169f11152 | b49c6e5dd236787f13a062ec528d724169f11152 |
| linux | linux | >= 7f882c2e353ca58695e9b4fcc9e97a9d4cbcf273 < 6c01ef65de0b321b2db1ef9abf8f1d15862b937e | 6c01ef65de0b321b2db1ef9abf8f1d15862b937e |
| linux | linux | >= 7f882c2e353ca58695e9b4fcc9e97a9d4cbcf273 < d9ef84a7c222497ecb5fdf93361c76931804825e | d9ef84a7c222497ecb5fdf93361c76931804825e |
| linux | linux | >= 7f882c2e353ca58695e9b4fcc9e97a9d4cbcf273 < 0143f282b15f7cedc0392ea10050fb6000fd16e6 | 0143f282b15f7cedc0392ea10050fb6000fd16e6 |
| linux | linux | >= 7f882c2e353ca58695e9b4fcc9e97a9d4cbcf273 < 41b7181a40af84448a2b144fb02d8bf32b7e9a23 | 41b7181a40af84448a2b144fb02d8bf32b7e9a23 |
| linux | linux | >= 7f882c2e353ca58695e9b4fcc9e97a9d4cbcf273 < 7bf744f2de0a848fb1d717f5831b03db96feae89 | 7bf744f2de0a848fb1d717f5831b03db96feae89 |
| linux | linux_kernel | < 4.14.326 | 4.14.326 |
| linux | linux_kernel | >= 0 < 5.10.197-1 | 5.10.197-1 |
| linux | linux_kernel | >= 0 < 6.1.55-1 | 6.1.55-1 |
| linux | linux_kernel | >= 0 < 6.5.6-1 | 6.5.6-1 |
| linux | linux_kernel | >= 0 < 6.5.6-1 | 6.5.6-1 |
| linux | linux_kernel | >= 4.15 < 4.19.295 | 4.19.295 |
| linux | linux_kernel | >= 4.20 < 5.4.257 | 5.4.257 |
| linux | linux_kernel | >= 5.11 < 5.15.133 | 5.15.133 |
| linux | linux_kernel | >= 5.16 < 6.1.55 | 6.1.55 |
| linux | linux_kernel | >= 5.5 < 5.10.197 | 5.10.197 |
| linux | linux_kernel | >= 6.2 < 6.5.5 | 6.5.5 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: media: dvb-usb-v2: af9035: Fix null-ptr-deref in af9035_i2c_master_xfer
vendor_redhat·2024-09-06·CVSS 5.5
CVE-2023-52915 [MEDIUM] CWE-476 kernel: media: dvb-usb-v2: af9035: Fix null-ptr-deref in af9035_i2c_master_xfer
kernel: media: dvb-usb-v2: af9035: Fix null-ptr-deref in af9035_i2c_master_xfer
In the Linux kernel, the following vulnerability has been resolved:
media: dvb-usb-v2: af9035: Fix null-ptr-deref in af9035_i2c_master_xfer
In af9035_i2c_master_xfer, msg is controlled by user. When msg[i].buf
is null and msg[i].len is zero, former checks on msg[i].buf would be
passed. Malicious data finally reach af9035_i2c_master_xfer. If accessing
msg[i].buf[0] without sanity check, null ptr deref would happen.
We add check on msg[i].len to prevent crash.
Similar commit:
commit 0ed554fd769a
("media: dvb-usb: az6027: fix null-ptr-deref in az6027_i2c_xfer()")
A NULL pointer dereference vulnerability was found in the af9035_i2c_master_xfer function of the dvb-usb-v2 driver in the Linux kernel. This issue occu
Debian
CVE-2023-52915: linux - In the Linux kernel, the following vulnerability has been resolved: media: dvb-...
vendor_debian·2023·CVSS 5.5
CVE-2023-52915 [MEDIUM] CVE-2023-52915: linux - In the Linux kernel, the following vulnerability has been resolved: media: dvb-...
In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb-v2: af9035: Fix null-ptr-deref in af9035_i2c_master_xfer In af9035_i2c_master_xfer, msg is controlled by user. When msg[i].buf is null and msg[i].len is zero, former checks on msg[i].buf would be passed. Malicious data finally reach af9035_i2c_master_xfer. If accessing msg[i].buf[0] without sanity check, null ptr deref would happen. We add check on msg[i].len to prevent crash. Similar commit: commit 0ed554fd769a ("media: dvb-usb: az6027: fix null-ptr-deref in az6027_i2c_xfer()")
Scope: local
bookworm: resolved (fixed in 6.1.55-1)
bullseye: resolved (fixed in 5.10.197-1)
forky: resolved (fixed in 6.5.6-1)
sid: resolved (fixed in 6.5.6-1)
trixie: resolved (fixed in 6.5.6-1)
OSV
CVE-2023-52915: In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb-v2: af9035: Fix null-ptr-deref in af9035_i2c_master_xfer In af9035_
osv·2024-09-06·CVSS 5.5
CVE-2023-52915 [MEDIUM] CVE-2023-52915: In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb-v2: af9035: Fix null-ptr-deref in af9035_i2c_master_xfer In af9035_
In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb-v2: af9035: Fix null-ptr-deref in af9035_i2c_master_xfer In af9035_i2c_master_xfer, msg is controlled by user. When msg[i].buf is null and msg[i].len is zero, former checks on msg[i].buf would be passed. Malicious data finally reach af9035_i2c_master_xfer. If accessing msg[i].buf[0] without sanity check, null ptr deref would happen. We add check on msg[i].len to prevent crash. Similar commit: commit 0ed554fd769a ("media: dvb-usb: az6027: fix null-ptr-deref in az6027_i2c_xfer()")
GHSA
GHSA-rpfq-qgpp-7qm9: In the Linux kernel, the following vulnerability has been resolved:
media: dvb-usb-v2: af9035: Fix null-ptr-deref in af9035_i2c_master_xfer
In af903
ghsa_unreviewed·2024-09-06
CVE-2023-52915 [MEDIUM] CWE-476 GHSA-rpfq-qgpp-7qm9: In the Linux kernel, the following vulnerability has been resolved:
media: dvb-usb-v2: af9035: Fix null-ptr-deref in af9035_i2c_master_xfer
In af903
In the Linux kernel, the following vulnerability has been resolved:
media: dvb-usb-v2: af9035: Fix null-ptr-deref in af9035_i2c_master_xfer
In af9035_i2c_master_xfer, msg is controlled by user. When msg[i].buf
is null and msg[i].len is zero, former checks on msg[i].buf would be
passed. Malicious data finally reach af9035_i2c_master_xfer. If accessing
msg[i].buf[0] without sanity check, null ptr deref would happen.
We add check on msg[i].len to prevent crash.
Similar commit:
commit 0ed554fd769a
("media: dvb-usb: az6027: fix null-ptr-deref in az6027_i2c_xfer()")
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/0143f282b15f7cedc0392ea10050fb6000fd16e6https://git.kernel.org/stable/c/41b7181a40af84448a2b144fb02d8bf32b7e9a23https://git.kernel.org/stable/c/6c01ef65de0b321b2db1ef9abf8f1d15862b937ehttps://git.kernel.org/stable/c/7bf744f2de0a848fb1d717f5831b03db96feae89https://git.kernel.org/stable/c/b2f54ed7739dfdf42c4df0a11131aad7c8635464https://git.kernel.org/stable/c/b49c6e5dd236787f13a062ec528d724169f11152https://git.kernel.org/stable/c/d9ef84a7c222497ecb5fdf93361c76931804825ehttps://git.kernel.org/stable/c/fa58d9db5cad4bb7bb694b6837e3b96d87554f2b
2024-09-06
Published