PT-2023-8773 · Linux+6 · Linux Kernel+6

Zhaolong Wang

·

Published

2023-12-22

·

Updated

2025-09-29

·

CVE-2023-52449

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a NULL pointer dereference in the Linux kernel's mtd module, specifically when the ftl notifier is triggered and tries to access gluebi->desc in gluebi read(). This occurs when both ftl.ko and gluebi.ko are loaded. The normal case involves obtaining gluebi->desc in gluebi get device() and accessing it in gluebi read(), but gluebi get device() is not executed in advance in the ftl add mtd() process, leading to the NULL pointer dereference. The solution involves running jffs2 on the UBI volume without considering working with ftl or mtdblock. This problem can be avoided by preventing gluebi from creating the mtdblock device after creating an mtd partition of the type MTD UBIVOLUME.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-17576
ALT-PU-2024-3291
ALT-PU-2024-4263
ALT-PU-2024-4623
ALT-PU-2024-4843
BDU:2024-01858
CVE-2023-52449
DLA-3840-1
DLA-3841-1
OESA-2024-1296
OESA-2024-1297
OESA-2024-1298
OESA-2024-1299
OESA-2024-1300
OESA-2024-1301
OPENSUSE-SU-2024_0857-1
OPENSUSE-SU-2024_0858-1
SUSE-SU-2024:0855-1
SUSE-SU-2024:0856-1
SUSE-SU-2024:0857-1
SUSE-SU-2024:0858-1
SUSE-SU-2024:0900-1
SUSE-SU-2024:0900-2
SUSE-SU-2024:0910-1
SUSE-SU-2024:0925-1
SUSE-SU-2024:0926-1
SUSE-SU-2024:0975-1
SUSE-SU-2024:0976-1
SUSE-SU-2024:0977-1
SUSE-SU-2024:1669-1
USN-6688-1
USN-6725-1
USN-6725-2
USN-6726-1
USN-6726-2
USN-6726-3
USN-6765-1
USN-6818-1
USN-6818-2
USN-6818-3
USN-6818-4
USN-6819-1
USN-6819-2
USN-6819-3
USN-6819-4
USN-6926-1
USN-6926-2
USN-6926-3
USN-6938-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu