CVE-2023-52693

MEDIUM

Linux Kernel 2.6.39-4.19.306 - Uninitialized Handle Exposure via ACPI Backlight Device Registration

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ACPI: video: check for error while searching for backlight device parent If acpi_get_parent() called in acpi_video_dev_register_backlight() fails, for example, because acpi_ut_acquire_mutex() fails inside acpi_get_parent), this can lead to incorrect (uninitialized) acpi_parent handle being passed to acpi_get_pci_dev() for detecting the parent pci device. Check acpi_get_parent() result and set parent device only in case of success. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Scores

CVSS v3 5.5
EPSS 0.0002
EPSS Percentile 5.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (20)
debian/debian_linux 10.0
Linux/Linux < 2.6.39
Linux/Linux 2.6.39
Linux/Linux 4.19.306 - 4.19.*
Linux/Linux 5.10.209 - 5.10.*
Linux/Linux 5.15.148 - 5.15.*
Linux/Linux 5.4.268 - 5.4.*
Linux/Linux 6.1.75 - 6.1.*
Linux/Linux 6.6.14 - 6.6.*
Linux/Linux 6.7.2 - 6.7.*
... and 10 more
Published May 17, 2024
Tracked Since Feb 18, 2026