CVE-2023-53681
In the Linux kernel, the following vulnerability has been resolved: bcache: Fix __bch_btree_node_alloc to make the failure behavior consistent In some specific situations, the return value of __bch_btree_node_alloc may be NULL.
Does this matter?
Lower severity and a low EPSS score (0.14%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: bcache: Fix __bch_btree_node_alloc to make the failure behavior consistent In some specific situations, the return value of __bch_btree_node_alloc may be NULL. This may lead to a potential NULL pointer dereference in caller function like a calling chain : btree_split->bch_btree_node_alloc->__bch_btree_node_alloc. Fix it by initializing the return value in __bch_btree_node_alloc.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.14% probability · 4th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/4514847aee18d9391a0cf3aad75d3567c72795a4Patch
- https://git.kernel.org/stable/c/587b4e8bb5dac682f09280ab35db4632b29d5ac4Patch
- https://git.kernel.org/stable/c/7ecea5ce3dc17339c280c75b58ac93d8c8620d9fPatch
- https://git.kernel.org/stable/c/80fca8a10b604afad6c14213fdfd816c4eda3ee4Patch
- https://git.kernel.org/stable/c/a4405f6ee03323410d7b10966fd67b35f71b1944Patch
- https://git.kernel.org/stable/c/b070f29a61436f6f8a2e3abc7ea4f4be81695198Patch
- https://git.kernel.org/stable/c/f67b0e3081f2a24170280a33ac66f6b112083c03Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.