CVE-2023-52794
Severity CVSS v4.0:
Pending analysis
Type:
CWE-125
Out-of-bounds Read
Publication date:
21/05/2024
Last modified:
06/03/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
thermal: intel: powerclamp: fix mismatch in get function for max_idle<br />
<br />
KASAN reported this<br />
<br />
[ 444.853098] BUG: KASAN: global-out-of-bounds in param_get_int+0x77/0x90<br />
[ 444.853111] Read of size 4 at addr ffffffffc16c9220 by task cat/2105<br />
...<br />
[ 444.853442] The buggy address belongs to the variable:<br />
[ 444.853443] max_idle+0x0/0xffffffffffffcde0 [intel_powerclamp]<br />
<br />
There is a mismatch between the param_get_int and the definition of<br />
max_idle. Replacing param_get_int with param_get_byte resolves this<br />
issue.
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.3 (including) | 6.5.13 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.6 (including) | 6.6.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/0a8585281b11e3a0723bba8d8085d61f0b55f37c
- https://git.kernel.org/stable/c/6a3866dbdcf39ac93e98708e6abced511733dc18
- https://git.kernel.org/stable/c/fae633cfb729da2771b5433f6b84ae7e8b4aa5f7
- https://git.kernel.org/stable/c/0a8585281b11e3a0723bba8d8085d61f0b55f37c
- https://git.kernel.org/stable/c/6a3866dbdcf39ac93e98708e6abced511733dc18
- https://git.kernel.org/stable/c/fae633cfb729da2771b5433f6b84ae7e8b4aa5f7