5.5
CVE-2023-52773
- EPSS 0.24%
- Veröffentlicht 21.05.2024 16:15:16
- Zuletzt bearbeitet 21.11.2024 08:40:33
- CVE-Watchlists
- Unerledigt
drm/amd/display: fix a NULL pointer dereference in amdgpu_dm_i2c_xfer()
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix a NULL pointer dereference in amdgpu_dm_i2c_xfer() When ddc_service_construct() is called, it explicitly checks both the link type and whether there is something on the link which will dictate whether the pin is marked as hw_supported. If the pin isn't set or the link is not set (such as from unloading/reloading amdgpu in an IGT test) then fail the amdgpu_dm_i2c_xfer() call.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 6.0 < 6.1.64
Linux ≫ Linux Kernel Version >= 6.2 < 6.5.13
Linux ≫ Linux Kernel Version >= 6.6 < 6.6.3
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.143 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-476 NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
https://git.kernel.org/stable/c/1d07b7e84276777dad3c8cfebdf8e739606f90c9
https://git.kernel.org/stable/c/5b14cf37b9f01de0b28c6f8960019d4c7883ce42
https://git.kernel.org/stable/c/b71f4ade1b8900d30c661d6c27f87c35214c398c
https://git.kernel.org/stable/c/fb5c134ca589fe670430acc9e7ebf2691ca2476d