SB2024060569 - NULL pointer dereference in Linux kernel drm i915 driver
Published: June 5, 2024 Updated: May 13, 2025
Security Bulletin ID
SB2024060569
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2023-52788)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the i915_perf_open_ioctl(), i915_perf_add_config_ioctl() and i915_perf_remove_config_ioctl() functions in drivers/gpu/drm/i915/i915_perf.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1566e8be73fd5fa424e88d2a4cffdc34f970f0e1
- https://git.kernel.org/stable/c/55db76caa782baa4a1bf02296e2773c38a524a3e
- https://git.kernel.org/stable/c/bf8e105030083e7b71591cdf437e464bcd8a0c09
- https://git.kernel.org/stable/c/10f49cdfd5fb342a1a9641930dc040c570694e98
- https://git.kernel.org/stable/c/471aa951bf1206d3c10d0daa67005b8e4db4ff83
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.140
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.64
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.5.13
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.3
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.7