usb: typec: tcpm: Fix NULL pointer dereference in tcpm_pd_svdm()
Published May 21, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.22%
Description
It is possible that typec_register_partner() returns ERR_PTR on failure. When port->partner is an error, a NULL pointer dereference may occur as shown below.
[91222.095236][ T319] typec port0: failed to register partner (-17) ... [91225.061491][ T319] Unable to handle kernel NULL pointer dereference at virtual address 000000000000039f [91225.274642][ T319] pc : tcpm_pd_data_request+0x310/0x13fc [91225.274646][ T319] lr : tcpm_pd_data_request+0x298/0x13fc [91225.308067][ T319] Call trace: [91225.308070][ T319] tcpm_pd_data_request+0x310/0x13fc [91225.308073][ T319] tcpm_pd_rx_handler+0x100/0x9e8 [91225.355900][ T319] kthread_worker_fn+0x178/0x58c [91225.355902][ T319] kthread+0x150/0x200 [91225.355905][ T319] ret_from_fork+0x10/0x30
Add a check for port->partner to avoid dereferencing a NULL pointer.
Affected products
-
- Version 5e1d4c49fbc8StatusaffectedConstraints<4987daf86c15
- Version 5e1d4c49fbc8StatusaffectedConstraints<9ee038590d80
- Version 5e1d4c49fbc8StatusaffectedConstraints<b37a168c0137
- Version 5e1d4c49fbc8StatusaffectedConstraints<e5f53a68a596
- Version 5e1d4c49fbc8StatusaffectedConstraints<e7a802447c49
- Version
-
- Version 5.12StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.12
- Version 5.15.138StatusunaffectedConstraints<=5.15.*
- Version 6.1.62StatusunaffectedConstraints<=6.1.*
- Version 6.5.11StatusunaffectedConstraints<=6.5.*
- Version 6.6.1StatusunaffectedConstraints<=6.6.*
- Version 6.7StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 5.12 · < 5.15.138
- ≥ 5.16 · < 6.1.62
- ≥ 6.2 · < 6.5.11
- ≥ 6.6 · < 6.6.1
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.8.1.el8_10
Fixed · RHSA-2024:4211
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-553.8.1.rt7.349.el8_10
Fixed · RHSA-2024:4352
Red Hat Enterprise Linux 9.4 Extended Update Support
kernel-0:5.14.0-427.81.1.el9_4
Fixed · RHSA-2025:13135
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.8.1.el8_10 | Fixed | RHSA-2024:4211 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-553.8.1.rt7.349.el8_10 | Fixed | RHSA-2024:4352 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | kernel-0:5.14.0-427.81.1.el9_4 | Fixed | RHSA-2025:13135 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2023-52877 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2282712 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59590 Advisory
- https://git.kernel.org/stable/c/4987daf86c152ff882d51572d154ad12e4ff3a4b Patch
- https://git.kernel.org/stable/c/9ee038590d808a95d16adf92818dcd4752273c08 Patch
- https://git.kernel.org/stable/c/b37a168c0137156042a0ca9626651b5a789e822b Patch
- https://git.kernel.org/stable/c/e5f53a68a596e04df3fde3099273435a30b6fdac Patch
- https://git.kernel.org/stable/c/e7a802447c491903aa7cb45967aa2a934a4e63fc Patch
- https://lore.kernel.org/linux-cve-announce/2024052122-CVE-2023-52877-0826@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2023-52877
- https://www.cve.org/CVERecord?id=CVE-2023-52877
Change history (0)
No recorded changes yet.