#VU90288 Out-of-bounds read in Linux kernel


Published: 2024-05-31

Vulnerability identifier: #VU90288

Vulnerability risk: Low

CVSSv3.1: 3.2 [AV:L/AC:L/PR:L/UI:U/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-52819

CWE-ID: CWE-125

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds read error within the drivers/gpu/drm/amd/powerplay/hwmgr/pptable_v1_0.h. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel:


External links
http://git.kernel.org/stable/c/60a00dfc7c5deafd1dd393beaf53224f7256dad6
http://git.kernel.org/stable/c/a63fd579e7b1c3a9ebd6e6c494d49b1b6cf5515e
http://git.kernel.org/stable/c/d50a56749e5afdc63491b88f5153c1aae00d4679
http://git.kernel.org/stable/c/8c1dbddbfcb051e82cea0c197c620f9dcdc38e92
http://git.kernel.org/stable/c/a237675aa1e62bbfaa341c535331c8656a508fa1
http://git.kernel.org/stable/c/d0725232da777840703f5f1e22f2e3081d712aa4
http://git.kernel.org/stable/c/7c68283f3166221af3df5791f0e13d3137a72216
http://git.kernel.org/stable/c/b3b8b7c040cf069da7afe11c5bd73b870b8f3d18
http://git.kernel.org/stable/c/0f0e59075b5c22f1e871fbd508d6e4f495048356


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability