VulnerabilityAnalyzed
CVE-2023-52607
In the Linux kernel, the following vulnerability has been resolved: powerpc/mm: Fix null-pointer dereference in pgtable_cache_add kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure.
MEDIUM 5.5EPSS 0.23%
Does this matter?
Lower severity and a low EPSS score (0.23%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: powerpc/mm: Fix null-pointer dereference in pgtable_cache_add kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure. Ensure the allocation was successful by checking the pointer validity.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.23% probability · 14th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/145febd85c3bcc5c74d87ef9a598fc7d9122d532Patch
- https://git.kernel.org/stable/c/21e45a7b08d7cd98d6a53c5fc5111879f2d96611Patch
- https://git.kernel.org/stable/c/aa28eecb43cac6e20ef14dfc50b8892c1fbcda5bPatch
- https://git.kernel.org/stable/c/ac3ed969a40357b0542d20f096a6d43acdfa6cc7Patch
- https://git.kernel.org/stable/c/d482d61025e303a2bef3733a011b6b740215cfa1Patch
- https://git.kernel.org/stable/c/f46c8a75263f97bda13c739ba1c90aced0d3b071Patch
- https://git.kernel.org/stable/c/f6781add1c311c17eff43e14c786004bbacf901ePatch
- https://git.kernel.org/stable/c/ffd29dc45bc0355393859049f6becddc3ed08f74Patch
- https://git.kernel.org/stable/c/145febd85c3bcc5c74d87ef9a598fc7d9122d532Patch
- https://git.kernel.org/stable/c/21e45a7b08d7cd98d6a53c5fc5111879f2d96611Patch
- https://git.kernel.org/stable/c/aa28eecb43cac6e20ef14dfc50b8892c1fbcda5bPatch
- https://git.kernel.org/stable/c/ac3ed969a40357b0542d20f096a6d43acdfa6cc7Patch
- https://git.kernel.org/stable/c/d482d61025e303a2bef3733a011b6b740215cfa1Patch
- https://git.kernel.org/stable/c/f46c8a75263f97bda13c739ba1c90aced0d3b071Patch
- https://git.kernel.org/stable/c/f6781add1c311c17eff43e14c786004bbacf901ePatch
- https://git.kernel.org/stable/c/ffd29dc45bc0355393859049f6becddc3ed08f74Patch
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.htmlPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.