PT-2022-6416 · Linux+2 · Linux Kernel+2
Published
2022-11-30
·
Updated
2026-03-13
·
CVE-2023-23005
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.2
Description
The issue is related to the misinterpretation of the
alloc memory type return value in the mm/memory-tiers.c file of the Linux kernel. This misinterpretation can lead to errors, potentially causing a denial of service. It is noted that there are no realistic cases in which a user can cause the alloc memory type error case to be reached, which has led to disputes about the vulnerability.Recommendations
To resolve the issue, update the Linux kernel to version 6.2 or later.
At the moment, there is no information about additional mitigation measures for versions prior to 6.2.
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Debian
Linux Kernel