PT-2023-9387 · Linux+3 · Linux Kernel+3

Nishanth Menon

·

Published

2023-09-05

·

Updated

2025-02-03

·

CVE-2023-52861

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a NULL pointer dereference in the Linux kernel's drm/bridge/ite-it66121.c component. This occurs when no monitor is connected and the sound card is opened from userspace. The vulnerability allows an attacker to cause a denial of service. To mitigate this, the kernel now returns an empty buffer of zeroes as the EDID information to the sound framework when there is no connector attached.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06984
CVE-2023-52861
SUSE-SU-2024:2008-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2190-1
SUSE-SU-2024:2571-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse