PT-2024-7864 · Linux+4 · Linux Kernel+4

Published

2024-02-05

·

Updated

2025-02-03

·

CVE-2023-52647

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a null pointer dereference in the mxc isi crossbar xlate streams() function. When translating source to sink streams in the crossbar subdev, the driver tries to locate the remote subdev connected to the sink pad. If the remote pad is null, the driver dereferences it, leading to a crash. The crash can be prevented by checking if the pad is null before using it and returning an error if it is.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-09366
CVE-2023-52647
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6816-1
USN-6817-1
USN-6817-2
USN-6817-3
USN-6878-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu