#VU90636 NULL pointer dereference in Linux kernel - CVE-2023-52567


Vulnerability identifier: #VU90636

Vulnerability risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2023-52567

CWE-ID: CWE-476

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the serial8250_handle_irq() function in drivers/tty/serial/8250/8250_port.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions


External links
https://git.kernel.org/stable/c/ee5732caaffba3a37e753fdb89b4958db9a61847
https://git.kernel.org/stable/c/c334650150c29234b0923476f51573ae1b2f252a
https://git.kernel.org/stable/c/bf3c728e3692cc6d998874f0f27d433117348742
https://git.kernel.org/stable/c/e14afa4450cb7e4cf93e993a765801203d41d014
https://git.kernel.org/stable/c/2b837f13a818f96304736453ac53b66a70aaa4f2
https://git.kernel.org/stable/c/e14f68a48fd445a083ac0750fafcb064df5f18f7
https://git.kernel.org/stable/c/3345cc5f02f1fb4c4dcb114706f2210d879ab933
https://git.kernel.org/stable/c/cce7fc8b29961b64fadb1ce398dc5ff32a79643b


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability