CVE-2023-52861
In the Linux kernel, the following vulnerability has been resolved: drm: bridge: it66121: Fix invalid connector dereference Fix the NULL pointer dereference when no monitor is connected, and the sound card is opened from userspace.
Does this matter?
Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: drm: bridge: it66121: Fix invalid connector dereference Fix the NULL pointer dereference when no monitor is connected, and the sound card is opened from userspace. Instead return an empty buffer (of zeroes) as the EDID information to the sound framework if there is no connector attached.
- CVSS 3.1
- 6.2 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.25% probability · 16th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/1374561a7cbc9a000b77bb0473bb2c19daf18d86Patch
- https://git.kernel.org/stable/c/1669d7b21a664aa531856ce85b01359a376baebcPatch
- https://git.kernel.org/stable/c/2c80c4f0d2845645f41cbb7c9304c8efbdbd4331Patch
- https://git.kernel.org/stable/c/d0375f6858c4ff7244b62b02eb5e93428e1916cdPatch
- https://git.kernel.org/stable/c/1374561a7cbc9a000b77bb0473bb2c19daf18d86Patch
- https://git.kernel.org/stable/c/1669d7b21a664aa531856ce85b01359a376baebcPatch
- https://git.kernel.org/stable/c/2c80c4f0d2845645f41cbb7c9304c8efbdbd4331Patch
- https://git.kernel.org/stable/c/d0375f6858c4ff7244b62b02eb5e93428e1916cdPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.