CVE-2023-52794

HIGH

Linux Kernel 6.3-6.5.12, 6.6.0-6.6.2, 6.7 - Out-of-bounds Read in intel_powerclamp max_idle Parameter

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: thermal: intel: powerclamp: fix mismatch in get function for max_idle KASAN reported this [ 444.853098] BUG: KASAN: global-out-of-bounds in param_get_int+0x77/0x90 [ 444.853111] Read of size 4 at addr ffffffffc16c9220 by task cat/2105 ... [ 444.853442] The buggy address belongs to the variable: [ 444.853443] max_idle+0x0/0xffffffffffffcde0 [intel_powerclamp] There is a mismatch between the param_get_int and the definition of max_idle. Replacing param_get_int with param_get_byte resolves this issue.

Scores

CVSS v3 7.1
EPSS 0.0024
EPSS Percentile 15.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (9)
Linux/Linux < 6.3
Linux/Linux 6.3
Linux/Linux 6.5.13 - 6.5.*
Linux/Linux 6.6.3 - 6.6.*
Linux/Linux 6.7
Linux/Linux ebf519710218814cf827adbf9111af081344c969 - 0a8585281b11e3a0723bba8d8085d61f0b55f37c
Linux/Linux ebf519710218814cf827adbf9111af081344c969 - 6a3866dbdcf39ac93e98708e6abced511733dc18
Linux/Linux ebf519710218814cf827adbf9111af081344c969 - fae633cfb729da2771b5433f6b84ae7e8b4aa5f7
linux/linux_kernel 6.3 - 6.5.13
Published May 21, 2024
Tracked Since Feb 18, 2026