-

CVE-2023-53336

In the Linux kernel, the following vulnerability has been resolved:

media: ipu-bridge: Fix null pointer deref on SSDB/PLD parsing warnings

When ipu_bridge_parse_rotation() and ipu_bridge_parse_orientation() run
sensor->adev is not set yet.

So if either of the dev_warn() calls about unknown values are hit this
will lead to a NULL pointer deref.

Set sensor->adev earlier, with a borrowed ref to avoid making unrolling
on errors harder, to fix this.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < 3de35e29cfddfe6bff762b15bcfe8d80bebac6cb
Version 485aa3df0dffa62d347ea4e0116f549338accc59
Status affected
Version < e08b091e33ecf6e4cb2c0c5820a69abe7673280b
Version 485aa3df0dffa62d347ea4e0116f549338accc59
Status affected
Version < 284be5693163343e1cf17c03917eecd1d6681bcf
Version 485aa3df0dffa62d347ea4e0116f549338accc59
Status affected
VendorLinux
Product Linux
Default Statusaffected
Version 5.16
Status affected
Version < 5.16
Version 0
Status unaffected
Version <= 6.4.*
Version 6.4.16
Status unaffected
Version <= 6.5.*
Version 6.5.3
Status unaffected
Version <= *
Version 6.6
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.053
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string