NULL pointer dereference in Linux kernel firmware google driver



Published: 2024-08-21
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2023-52893
CWE-ID CWE-476
Exploitation vector Local
Public exploit N/A
Vulnerable software
Subscribe
Linux kernel
Operating systems & Components / Operating system

Vendor Linux Foundation

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) NULL pointer dereference

EUVDB-ID: #VU96349

Risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-52893

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the gsmi_get_variable() function in drivers/firmware/google/gsmi.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions

External links

http://git.kernel.org/stable/c/ee5763ef829bd923033510de6d1df7c73f085e4b
http://git.kernel.org/stable/c/32313c11bdc8a02c577abaf865be3664ab30410a
http://git.kernel.org/stable/c/ffef77794fb5f1245c3249b86342bad2299accb5
http://git.kernel.org/stable/c/ae2a9dcc8caa60b1e14671294e5ec902ea5d1dfd
http://git.kernel.org/stable/c/eb0421d90f916dffe96b4c049ddf01c0c50620d2
http://git.kernel.org/stable/c/6646d769fdb0ce4318ef9afd127f8526d1ca8393
http://git.kernel.org/stable/c/a769b05eeed7accc4019a1ed9799dd72067f1ce8


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###