PT-2023-9387 · Linux+3 · Linux Kernel+3

Nishanth Menon

·

Publicado

2023-09-05

·

Atualizado

2025-02-03

·

CVE-2023-52861

CVSS v3.1

6.2

Média

VetorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a NULL pointer dereference in the Linux kernel's drm/bridge/ite-it66121.c component. This occurs when no monitor is connected and the sound card is opened from userspace. The vulnerability allows an attacker to cause a denial of service. To mitigate this, the kernel now returns an empty buffer of zeroes as the EDID information to the sound framework when there is no connector attached.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-06984
CVE-2023-52861
SUSE-SU-2024:2008-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2190-1
SUSE-SU-2024:2571-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1

Produtos afetados

Astra Linux
Linux Kernel
Red Os
Suse