CVE-2023-52495
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
11/03/2024
Last modified:
14/02/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
soc: qcom: pmic_glink_altmode: fix port sanity check<br />
<br />
The PMIC GLINK altmode driver currently supports at most two ports.<br />
<br />
Fix the incomplete port sanity check on notifications to avoid<br />
accessing and corrupting memory beyond the port array if we ever get a<br />
notification for an unsupported port.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.3 (including) | 6.6.15 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.7.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/532a5557da6892a6b2d5793052e1bce1f4c9e177
- https://git.kernel.org/stable/c/c4fb7d2eac9ff9bfc35a2e4d40c7169a332416e0
- https://git.kernel.org/stable/c/d26edf4ee3672cc9828f2a3ffae34086a712574d
- https://git.kernel.org/stable/c/532a5557da6892a6b2d5793052e1bce1f4c9e177
- https://git.kernel.org/stable/c/c4fb7d2eac9ff9bfc35a2e4d40c7169a332416e0
- https://git.kernel.org/stable/c/d26edf4ee3672cc9828f2a3ffae34086a712574d