PT-2023-3458 · Linux+1 · Linux Kernel+1

Published

2023-01-27

·

Updated

2025-03-07

·

CVE-2023-3359

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the brcm nvram parse() function in the Linux kernel, specifically in the drivers/nvmem/brcm nvram.c file. It is caused by a lack of check for the return value of kzalloc(), which can lead to a NULL pointer dereference. This could allow an attacker to cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-14046
ALT-PU-2024-6818
AZL-27332
AZL-27347
BDU:2023-03644
CVE-2023-3359

Affected Products

Alt Linux
Linux Kernel