PT-2024-8309 · Linux+5 · Linux Kernel+5

Published

2024-01-05

·

Updated

2025-03-28

·

CVE-2023-52678

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the drm/amdkfd component of the Linux kernel, where a vulnerability is caused by incorrect error handling. This can lead to a denial of service. The vulnerability is resolved by confirming that a list is non-empty before utilizing list first entry in kfd topology.c. Specifically, the functions kfd create indirect link prop() and kfd add peer prop() are warned about potential NULL values for gpu link, iolink1, and iolink2.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-09862
CVE-2023-52678
SUSE-SU-2024:2008-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2135-1
SUSE-SU-2024:2190-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20249-1
USN-6818-1
USN-6818-2
USN-6818-3
USN-6818-4
USN-6819-1
USN-6819-2
USN-6819-3
USN-6819-4

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu