CVE-2023-52893

MEDIUM

Linux Kernel 3.0-4.14.303 - Null Pointer Dereference in gsmi_get_variable

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: gsmi: fix null-deref in gsmi_get_variable We can get EFI variables without fetching the attribute, so we must allow for that in gsmi. commit 859748255b43 ("efi: pstore: Omit efivars caching EFI varstore access layer") added a new get_variable call with attr=NULL, which triggers panic in gsmi.

Scores

CVSS v3 5.5
EPSS 0.0024
EPSS Percentile 15.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (18)
Linux/Linux < 3.0
Linux/Linux 3.0
Linux/Linux 4.14.304 - 4.14.*
Linux/Linux 4.19.271 - 4.19.*
Linux/Linux 5.10.165 - 5.10.*
Linux/Linux 5.15.90 - 5.15.*
Linux/Linux 5.4.230 - 5.4.*
Linux/Linux 6.1.8 - 6.1.*
Linux/Linux 6.2
Linux/Linux 74c5b31c6618f01079212332b2e5f6c42f2d6307 - 32313c11bdc8a02c577abaf865be3664ab30410a
... and 8 more
Published Aug 21, 2024
Tracked Since Feb 18, 2026