PT-2024-2006 · Linux+6 · Linux Kernel+6

Fedor Pchelkin

·

Published

2024-01-04

·

Updated

2025-09-29

·

CVE-2023-52443

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.7.0-rc2-dirty #16
Description The vulnerability is related to the apparmor module in the Linux kernel. When processing a packed profile in unpack profile(), a string ":samba-dcerpcd" is unpacked as a fully-qualified name and then passed to aa splitn fqname(). This function treats the string as only containing a namespace, returning NULL for tmpname while tmpns is non-NULL. Later, aa alloc profile() crashes as the new profile name is NULL, resulting in a general protection fault. The issue is caused by the fact that nothing can prevent the unpacked "name" from being in a form like ":samba-dcerpcd", which is passed from userspace. To mitigate this, the whole profile set replacement should be denied in such cases, and the user should be informed with EPROTO and an explaining message.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-17576
ALT-PU-2024-3291
ALT-PU-2024-4263
ALT-PU-2024-4623
ALT-PU-2024-4843
BDU:2024-01867
CVE-2023-52443
DLA-3840-1
DLA-3841-1
OESA-2024-1392
OESA-2024-1393
OESA-2024-1394
OESA-2024-1395
OESA-2024-1396
OESA-2024-1397
OPENSUSE-SU-2024_0857-1
OPENSUSE-SU-2024_0858-1
SUSE-SU-2024:0855-1
SUSE-SU-2024:0856-1
SUSE-SU-2024:0857-1
SUSE-SU-2024:0858-1
SUSE-SU-2024:0900-1
SUSE-SU-2024:0900-2
SUSE-SU-2024:0910-1
SUSE-SU-2024:0925-1
SUSE-SU-2024:0926-1
SUSE-SU-2024:0975-1
SUSE-SU-2024:0976-1
SUSE-SU-2024:0977-1
USN-6688-1
USN-6725-1
USN-6725-2
USN-6726-1
USN-6726-2
USN-6726-3
USN-6765-1
USN-6818-1
USN-6818-2
USN-6818-3
USN-6818-4
USN-6819-1
USN-6819-2
USN-6819-3
USN-6819-4
USN-6926-1
USN-6926-2
USN-6926-3

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu