CVE-2023-52596

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
06/03/2024
Last modified:
14/02/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> sysctl: Fix out of bounds access for empty sysctl registers<br /> <br /> When registering tables to the sysctl subsystem there is a check to see<br /> if header is a permanently empty directory (used for mounts). This check<br /> evaluates the first element of the ctl_table. This results in an out of<br /> bounds evaluation when registering empty directories.<br /> <br /> The function register_sysctl_mount_point now passes a ctl_table of size<br /> 1 instead of size 0. It now relies solely on the type to identify<br /> a permanently empty register.<br /> <br /> Make sure that the ctl_table has at least one element before testing for<br /> permanent emptiness.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.6.16 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.7.4 (excluding)