#VU91241 NULL pointer dereference in Linux kernel


Published: 2024-06-05

Vulnerability identifier: #VU91241

Vulnerability risk: Low

CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-52585

CWE-ID: CWE-476

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the amdgpu_ras_query_error_status_helper() function in drivers/gpu/drm/amd/amdgpu/amdgpu_ras.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel:


External links
http://git.kernel.org/stable/c/195a6289282e039024ad30ba66e6f94a4d0fbe49
http://git.kernel.org/stable/c/b8d55a90fd55b767c25687747e2b24abd1ef8680
http://git.kernel.org/stable/c/467139546f3fb93913de064461b1a43a212d7626
http://git.kernel.org/stable/c/0eb296233f86750102aa43b97879b8d8311f249a
http://git.kernel.org/stable/c/7e6d6f27522bcd037856234b720ff607b9c4a09b
http://git.kernel.org/stable/c/92cb363d16ac1e41c9764cdb513d0e89a6ff4915
http://git.kernel.org/stable/c/c364e7a34c85c2154fb2e47561965d5b5a0b69b1


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability