media: vidtv: mux: Add check and kfree for kstrdup
Published May 21, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.24%
Description
Add check for the return value of kstrdup() and return the error if it fails in order to avoid NULL pointer dereference. Moreover, use kfree() in the later error handling in order to avoid memory leak.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.10StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.10
- Version 5.10.201StatusunaffectedConstraints<=5.10.*
- Version 5.15.139StatusunaffectedConstraints<=5.15.*
- Version 6.1.63StatusunaffectedConstraints<=6.1.*
- Version 6.5.12StatusunaffectedConstraints<=6.5.*
- Version 6.6.2StatusunaffectedConstraints<=6.6.*
- Version 6.7StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 5.10 · < 5.10.201
- ≥ 5.11 · < 5.15.139
- ≥ 5.16 · < 6.1.63
- ≥ 6.2 · < 6.5.12
- ≥ 6.6 · < 6.6.2
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (12)
- https://access.redhat.com/security/cve/CVE-2023-52841 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2282708 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59554 Advisory
- https://git.kernel.org/stable/c/1fd6eb12642e0c32692924ff359c07de4b781d78 Patch
- https://git.kernel.org/stable/c/64863ba8e6b7651d994c6e6d506cc8aa2ac45edb Patch
- https://git.kernel.org/stable/c/980be4c3b0d51c0f873fd750117774561c66cf68 Patch
- https://git.kernel.org/stable/c/a254ee1ddc592ae1efcce96b8c014e1bd2d5a2b4 Patch
- https://git.kernel.org/stable/c/aae7598aff291d4d140be1355aa20930af948785 Patch
- https://git.kernel.org/stable/c/cb13001411999adb158b39e76d94705eb2da100d Patch
- https://lore.kernel.org/linux-cve-announce/2024052111-CVE-2023-52841-1157@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2023-52841
- https://www.cve.org/CVERecord?id=CVE-2023-52841
Change history (0)
No recorded changes yet.