CVE-2023-52459

MEDIUM

Linux Kernel 6.6-6.6.13 - NULL Pointer Dereference in V4L Async List Deletion

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: media: v4l: async: Fix duplicated list deletion The list deletion call dropped here is already called from the helper function in the line before. Having a second list_del() call results in either a warning (with CONFIG_DEBUG_LIST=y): list_del corruption, c46c8198->next is LIST_POISON1 (00000100) If CONFIG_DEBUG_LIST is disabled the operation results in a kernel error due to NULL pointer dereference.

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 12.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (9)
Linux/Linux < 6.6
Linux/Linux 28a1295795d85a25f2e7dd391c43969e95fcb341 - 3de6ee94aae701fa949cd3b5df6b6a440ddfb8f2
Linux/Linux 28a1295795d85a25f2e7dd391c43969e95fcb341 - 49d82811428469566667f22749610b8c132cdb3e
Linux/Linux 28a1295795d85a25f2e7dd391c43969e95fcb341 - b7062628caeaec90e8f691ebab2d70f31b7b6b91
Linux/Linux 6.6
Linux/Linux 6.6.14 - 6.6.*
Linux/Linux 6.7.2 - 6.7.*
Linux/Linux 6.8
linux/linux_kernel 6.6.0 - 6.6.14
Published Feb 23, 2024
Tracked Since Feb 18, 2026