SB2024070176 - Resource management error in Linux kernel master mipi-i3c-hci driver
Published: July 1, 2024 Updated: May 13, 2025
Security Bulletin ID
SB2024070176
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2023-52763)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the hci_dat_v1_init(), hci_dat_v1_cleanup() and hci_dat_v1_free_entry() functions in drivers/i3c/master/mipi-i3c-hci/dat_v1.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/39c71357e68e2f03766f9321b9f4882e49ff1442
- https://git.kernel.org/stable/c/e64d23dc65810be4e3395d72df0c398f60c991f9
- https://git.kernel.org/stable/c/3cb79a365e7cce8f121bba91312e2ddd206b9781
- https://git.kernel.org/stable/c/eed74230435c61eeb58abaa275b1820e6a4b7f02
- https://git.kernel.org/stable/c/b53e9758a31c683fc8615df930262192ed5f034b
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.140
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.64
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.5.13
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.3
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.7