pstore/platform: Add check for kstrdup
Published May 21, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.22%
Description
Add check for the return value of kstrdup() and return the error if it fails in order to avoid NULL pointer dereference.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 5.8
Unaffected
- ≥ 0, < 5.8
- ≥ 5.10.201, ≤ 5.10.*
- ≥ 5.15.139, ≤ 5.15.*
- ≥ 6.1.63, ≤ 6.1.*
- ≥ 6.5.12, ≤ 6.5.*
- ≥ 6.6.2, ≤ 6.6.*
- 6.7
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
- ≥ 5.8 · < 5.10.201
- ≥ 5.11 · < 5.15.139
- ≥ 5.16 · < 6.1.63
- ≥ 6.2 · < 6.5.12
- ≥ 6.6 · < 6.6.2
-
Affected
- 5.8
-
Affected
- 563ca40ddf40
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Linux | Linux Kernel | unknown | Affected
|
| Linux | Linux Kernel | unknown | Affected
|
Red Hat Enterprise Linux 9
kernel-0:5.14.0-503.11.1.el9_5
Fixed · RHSA-2024:9315
Red Hat Enterprise Linux 9
kernel-0:5.14.0-503.11.1.el9_5
Fixed · RHSA-2024:9315
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-503.11.1.el9_5 | Fixed | RHSA-2024:9315 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-503.11.1.el9_5 | Fixed | RHSA-2024:9315 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (12)
- https://access.redhat.com/security/cve/CVE-2023-52869 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2282622 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59582 Advisory
- https://git.kernel.org/stable/c/1c426da79f9fc7b761021b5eb44185ba119cd44a Patch
- https://git.kernel.org/stable/c/379b120e4f27fd1cf636a5f85570c4d240a3f688 Patch
- https://git.kernel.org/stable/c/63f637309baadf81a095f2653e3b807d4b5814b9 Patch
- https://git.kernel.org/stable/c/a19d48f7c5d57c0f0405a7d4334d1d38fe9d3c1c Patch
- https://git.kernel.org/stable/c/ad5cb6deb41417ef41b9d6ff54f789212108606f Patch
- https://git.kernel.org/stable/c/bb166bdae1a7d7db30e9be7e6ccaba606debc05f Patch
- https://lore.kernel.org/linux-cve-announce/2024052120-CVE-2023-52869-6f57@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2023-52869
- https://www.cve.org/CVERecord?id=CVE-2023-52869
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data