CVE-2023-52789

MEDIUM

Linux Kernel < 4.14.331 - NULL Pointer Dereference in vcc_probe()

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: tty: vcc: Add check for kstrdup() in vcc_probe() Add check for the return value of kstrdup() and return the error, if it fails in order to avoid NULL pointer dereference.

Scores

CVSS v3 5.5
EPSS 0.0025
EPSS Percentile 16.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (21)
Linux/Linux < 4.14
Linux/Linux 4.14
Linux/Linux 4.14.331 - 4.14.*
Linux/Linux 4.19.300 - 4.19.*
Linux/Linux 5.10.202 - 5.10.*
Linux/Linux 5.15.140 - 5.15.*
Linux/Linux 5.4.262 - 5.4.*
Linux/Linux 5d171050e28f823aeb040f2830da4d3422b54b63 - 38cd56fc9de78bf3c878790785e8c231116ef9d3
Linux/Linux 5d171050e28f823aeb040f2830da4d3422b54b63 - 460284dfb10b207980c6f3f7046e33446ceb38ac
Linux/Linux 5d171050e28f823aeb040f2830da4d3422b54b63 - 4a24a31826246b15477399febd13292b0c9f0ee9
... and 11 more
Published May 21, 2024
Tracked Since Feb 18, 2026