CVE-2023-52450

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
22/02/2024
Last modified:
18/03/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> perf/x86/intel/uncore: Fix NULL pointer dereference issue in upi_fill_topology()<br /> <br /> Get logical socket id instead of physical id in discover_upi_topology()<br /> to avoid out-of-bound access on &amp;#39;upi = &amp;type-&gt;topology[nid][idx];&amp;#39; line<br /> that leads to NULL pointer dereference in upi_fill_topology()

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2.0 (including) 6.6.14 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7.0 (including) 6.7.2 (excluding)