CVE-2023-52893
MEDIUMLinux Kernel 3.0-4.14.303 - Null Pointer Dereference in gsmi_get_variable
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: gsmi: fix null-deref in gsmi_get_variable We can get EFI variables without fetching the attribute, so we must allow for that in gsmi. commit 859748255b43 ("efi: pstore: Omit efivars caching EFI varstore access layer") added a new get_variable call with attr=NULL, which triggers panic in gsmi.
References (7)
Core 7
Core References
Scores
CVSS v3
5.5
EPSS
0.0024
EPSS Percentile
15.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-476
Status
published
Products (18)
Linux/Linux
< 3.0
Linux/Linux
3.0
Linux/Linux
4.14.304 - 4.14.*
Linux/Linux
4.19.271 - 4.19.*
Linux/Linux
5.10.165 - 5.10.*
Linux/Linux
5.15.90 - 5.15.*
Linux/Linux
5.4.230 - 5.4.*
Linux/Linux
6.1.8 - 6.1.*
Linux/Linux
6.2
Linux/Linux
74c5b31c6618f01079212332b2e5f6c42f2d6307 - 32313c11bdc8a02c577abaf865be3664ab30410a
... and 8 more
Published
Aug 21, 2024
Tracked Since
Feb 18, 2026