cbcvebase.
CVE-2023-52918
published 2024-10-22

CVE-2023-52918: In the Linux kernel, the following vulnerability has been resolved: media: pci: cx23885: check cx23885_vdev_init() return cx23885_vdev_init() can return a NULL…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.0th percentile
In the Linux kernel, the following vulnerability has been resolved: media: pci: cx23885: check cx23885_vdev_init() return cx23885_vdev_init() can return a NULL pointer, but that pointer is used in the next line without a check. Add a NULL pointer check and go to the error unwind if it is NULL.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= e47f30b140333525ea682ec672641b470da1e599 < 8e31b096e2e1949bc8f0be019c9ae70d414404c68e31b096e2e1949bc8f0be019c9ae70d414404c6
linuxlinux>= e47f30b140333525ea682ec672641b470da1e599 < 199a42fc4c45e8b7f19efeb15dbc36889a599ac2199a42fc4c45e8b7f19efeb15dbc36889a599ac2
linuxlinux>= e47f30b140333525ea682ec672641b470da1e599 < e7385510e2550a9f8b6f3d5f33c5b894ab9ba976e7385510e2550a9f8b6f3d5f33c5b894ab9ba976
linuxlinux>= e47f30b140333525ea682ec672641b470da1e599 < a5f1d30c51c485cec7a7de60205667c3ff86c303a5f1d30c51c485cec7a7de60205667c3ff86c303
linuxlinux>= e47f30b140333525ea682ec672641b470da1e599 < 06ee04a907d64ee3910fecedd05d7f1be4b1b70e06ee04a907d64ee3910fecedd05d7f1be4b1b70e
linuxlinux>= e47f30b140333525ea682ec672641b470da1e599 < b1397fb4a779fca560c43d2acf6702d41b4a495bb1397fb4a779fca560c43d2acf6702d41b4a495b
linuxlinux>= e47f30b140333525ea682ec672641b470da1e599 < 15126b916e39b0cb67026b0af3c014bfeb1f76b315126b916e39b0cb67026b0af3c014bfeb1f76b3
linuxlinux_kernel< 4.19.3214.19.321
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 4.20 < 5.4.2835.4.283
linuxlinux_kernel>= 5.11 < 5.15.1665.15.166
linuxlinux_kernel>= 5.16 < 6.1.1076.1.107
linuxlinux_kernel>= 5.5 < 5.10.2255.10.225
linuxlinux_kernel>= 6.2 < 6.6.486.6.48

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.