5.5

CVE-2023-52893

gsmi: fix null-deref in gsmi_get_variable

In the Linux kernel, the following vulnerability has been resolved:

gsmi: fix null-deref in gsmi_get_variable

We can get EFI variables without fetching the attribute, so we must
allow for that in gsmi.

commit 859748255b43 ("efi: pstore: Omit efivars caching EFI varstore
access layer") added a new get_variable call with attr=NULL, which
triggers panic in gsmi.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version >= 3.0 < 4.14.304
LinuxLinux Kernel Version >= 4.15 < 4.19.271
LinuxLinux Kernel Version >= 4.20 < 5.4.230
LinuxLinux Kernel Version >= 5.5 < 5.10.165
LinuxLinux Kernel Version >= 5.11 < 5.15.90
LinuxLinux Kernel Version >= 5.16 < 6.1.8
LinuxLinux Kernel Version6.2 Updaterc1
LinuxLinux Kernel Version6.2 Updaterc2
LinuxLinux Kernel Version6.2 Updaterc3
LinuxLinux Kernel Version6.2 Updaterc4
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.01% 0.018
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://git.kernel.org/stable/c/32313c11bdc8a02c577abaf865be3664ab30410a
Patch
https://git.kernel.org/stable/c/6646d769fdb0ce4318ef9afd127f8526d1ca8393
Patch
https://git.kernel.org/stable/c/a769b05eeed7accc4019a1ed9799dd72067f1ce8
Patch
https://git.kernel.org/stable/c/ae2a9dcc8caa60b1e14671294e5ec902ea5d1dfd
Patch
https://git.kernel.org/stable/c/eb0421d90f916dffe96b4c049ddf01c0c50620d2
Patch
https://git.kernel.org/stable/c/ee5763ef829bd923033510de6d1df7c73f085e4b
Patch
https://git.kernel.org/stable/c/ffef77794fb5f1245c3249b86342bad2299accb5
Patch