CVE-2023-52976

MEDIUM

Linux Kernel 5.1.16-5.4.232 - NULL Pointer Dereference in EFI Memory Reservation

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: efi: fix potential NULL deref in efi_mem_reserve_persistent When iterating on a linked list, a result of memremap is dereferenced without checking it for NULL. This patch adds a check that falls back on allocating a new page in case memremap doesn't succeed. Found by Linux Verification Center (linuxtesting.org) with SVACE. [ardb: return -ENOMEM instead of breaking out of the loop]

Scores

CVSS v3 5.5
EPSS 0.0025
EPSS Percentile 16.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (16)
Linux/Linux < 5.2
Linux/Linux 18df7577adae6c6c778bf774b3aebcacbc1fb439 - 87d4ff18738fd71e7e3c10827c80257da6283697
Linux/Linux 18df7577adae6c6c778bf774b3aebcacbc1fb439 - 966d47e1f27c45507c5df82b2a2157e5a4fd3909
Linux/Linux 18df7577adae6c6c778bf774b3aebcacbc1fb439 - a2e6a9ff89f13666a1c3ff7195612ab949ea9afc
Linux/Linux 18df7577adae6c6c778bf774b3aebcacbc1fb439 - d8fc0b5fb3e816a4a8684bcd3ed02cbef0fce23c
Linux/Linux 18df7577adae6c6c778bf774b3aebcacbc1fb439 - d92a25627bcdf264183670da73c9a60c0bac327e
Linux/Linux 5.1.16 - 5.2
Linux/Linux 5.10.168 - 5.10.*
Linux/Linux 5.15.93 - 5.15.*
Linux/Linux 5.2
... and 6 more
Published Mar 27, 2025
Tracked Since Feb 18, 2026