CVE-2023-52794
HIGHLinux Kernel 6.3-6.5.12, 6.6.0-6.6.2, 6.7 - Out-of-bounds Read in intel_powerclamp max_idle Parameter
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: thermal: intel: powerclamp: fix mismatch in get function for max_idle KASAN reported this [ 444.853098] BUG: KASAN: global-out-of-bounds in param_get_int+0x77/0x90 [ 444.853111] Read of size 4 at addr ffffffffc16c9220 by task cat/2105 ... [ 444.853442] The buggy address belongs to the variable: [ 444.853443] max_idle+0x0/0xffffffffffffcde0 [intel_powerclamp] There is a mismatch between the param_get_int and the definition of max_idle. Replacing param_get_int with param_get_byte resolves this issue.
References (3)
Core 3
Scores
CVSS v3
7.1
EPSS
0.0024
EPSS Percentile
15.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-125
Status
published
Products (9)
Linux/Linux
< 6.3
Linux/Linux
6.3
Linux/Linux
6.5.13 - 6.5.*
Linux/Linux
6.6.3 - 6.6.*
Linux/Linux
6.7
Linux/Linux
ebf519710218814cf827adbf9111af081344c969 - 0a8585281b11e3a0723bba8d8085d61f0b55f37c
Linux/Linux
ebf519710218814cf827adbf9111af081344c969 - 6a3866dbdcf39ac93e98708e6abced511733dc18
Linux/Linux
ebf519710218814cf827adbf9111af081344c969 - fae633cfb729da2771b5433f6b84ae7e8b4aa5f7
linux/linux_kernel
6.3 - 6.5.13
Published
May 21, 2024
Tracked Since
Feb 18, 2026