#VU96349 NULL pointer dereference in Linux kernel


Published: 2024-08-21

Vulnerability identifier: #VU96349

Vulnerability risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-52893

CWE-ID: CWE-476

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the gsmi_get_variable() function in drivers/firmware/google/gsmi.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel:


External links
http://git.kernel.org/stable/c/ee5763ef829bd923033510de6d1df7c73f085e4b
http://git.kernel.org/stable/c/32313c11bdc8a02c577abaf865be3664ab30410a
http://git.kernel.org/stable/c/ffef77794fb5f1245c3249b86342bad2299accb5
http://git.kernel.org/stable/c/ae2a9dcc8caa60b1e14671294e5ec902ea5d1dfd
http://git.kernel.org/stable/c/eb0421d90f916dffe96b4c049ddf01c0c50620d2
http://git.kernel.org/stable/c/6646d769fdb0ce4318ef9afd127f8526d1ca8393
http://git.kernel.org/stable/c/a769b05eeed7accc4019a1ed9799dd72067f1ce8


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability