PT-2023-9756 · Linux+8 · Linux Kernel+8
Published
2023-09-21
·
Updated
2026-03-14
·
CVE-2023-52811
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to the ibmvfc driver in the Linux kernel, where a BUG ON assertion is triggered when an empty event pool is encountered. This can lead to a junk event pointer being returned, causing problems. The BUG ON is a historical artifact and is considered bad practice except in unrecoverable scenarios. The driver can recover from this situation, and the BUG ON has been removed in favor of returning a NULL pointer in the case of an empty event pool. All call sites to the affected function have been updated to check for a NULL pointer and perform the appropriate failure or recovery action.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Astra Linux
Centos
Debian
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse