CVE-2023-52868

HIGH

Linux Kernel 2.6.25-4.14.329 - Out-of-bounds Write in Thermal Core ID Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: thermal: core: prevent potential string overflow The dev->id value comes from ida_alloc() so it's a number between zero and INT_MAX. If it's too high then these sprintf()s will overflow.

Scores

CVSS v3 7.8
EPSS 0.0024
EPSS Percentile 14.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (21)
Linux/Linux < 2.6.25
Linux/Linux 2.6.25
Linux/Linux 203d3d4aa482339b4816f131f713e1b8ee37f6dd - 0f6b3be28c4d62ef6498133959c72266629bea97
Linux/Linux 203d3d4aa482339b4816f131f713e1b8ee37f6dd - 3091ab943dfc7b2578599b0fe203350286fab5bb
Linux/Linux 203d3d4aa482339b4816f131f713e1b8ee37f6dd - 3a8f4e58e1ee707b4f46a1000b40b86ea3dd509c
Linux/Linux 203d3d4aa482339b4816f131f713e1b8ee37f6dd - 3f795fb35c2d8a637efe76b4518216c9319b998c
Linux/Linux 203d3d4aa482339b4816f131f713e1b8ee37f6dd - 6ad1bf47fbe5750c4d5d8e41337665e193e2c521
Linux/Linux 203d3d4aa482339b4816f131f713e1b8ee37f6dd - 77ff34a56b695e228e6daf30ee30be747973d6e8
Linux/Linux 203d3d4aa482339b4816f131f713e1b8ee37f6dd - b55f0a9f865be75ca1019aad331f3225f7b50ce8
Linux/Linux 203d3d4aa482339b4816f131f713e1b8ee37f6dd - c99626092efca3061b387043d4a7399bf75fbdd5
... and 11 more
Published May 21, 2024
Tracked Since Feb 18, 2026