目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2023-52508— Linux kernel 安全漏洞

AI Predicted 4.9 Difficulty: Hard EPSS 0.22% · P13

Possible ATT&CK Techniques 1AI

T1211 · Exploitation for Stealth

Affected Version Matrix 10

ベンダープロダクトVersion Rangeステータス
LinuxLinux827fc630e4c8087df5a8e8ee013b686bd6f13736< be90c9e29dd59b7d19a73297a1590ff3ec1d22eaaffected
827fc630e4c8087df5a8e8ee013b686bd6f13736< dd46b3ac7322baf3772b33b29726e94f98289db7affected
827fc630e4c8087df5a8e8ee013b686bd6f13736< 8ae5b3a685dc59a8cf7ccfe0e850999ba9727a3caffected
7a41fdf27a4b1ee565ce5bf3e409b2df0b8514c4affected
5.18.18< 5.19affected
5.19affected
< 5.19unaffected
6.1.56≤ 6.1.*unaffected
… +2 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2023-52508の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
nvme-fc: Prevent null pointer dereference in nvme_fc_io_getuuid()
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: nvme-fc: Prevent null pointer dereference in nvme_fc_io_getuuid() The nvme_fc_fcp_op structure describing an AEN operation is initialized with a null request structure pointer. An FC LLDD may make a call to nvme_fc_io_getuuid passing a pointer to an nvmefc_fcp_req for an AEN operation. Add validation of the request structure pointer before dereference.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于空指针取消引用。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 827fc630e4c8087df5a8e8ee013b686bd6f13736 ~ be90c9e29dd59b7d19a73297a1590ff3ec1d22ea -
LinuxLinux 5.19 -

II. CVE-2023-52508の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2023-52508のインテリジェンス情報

登录查看更多情报信息。

CVE-2023-52508 其他参考 (2)

Same Patch Batch · Linux · 2024-03-02 · 57 CVEs total

CVE-2023-525159.8 CRITICALRDMA/srp: Do not call scsi_done() from srp_abort()
CVE-2023-525308.8 HIGHwifi: mac80211: fix potential key use-after-free
CVE-2023-525228.8 HIGHnet: fix possible store tearing in neigh_periodic_work()
CVE-2023-525028.8 HIGHnet: nfc: fix races in nfc_llcp_sock_get() and nfc_llcp_sock_get_sn()
CVE-2024-266218.2 HIGHmm: huge_memory: don't force huge page alignment on 32 bit
CVE-2023-525747.8 HIGHteam: fix null-ptr-deref when team device type is changed
CVE-2023-525097.8 HIGHravb: Fix use-after-free issue in ravb_tx_timeout_work()
CVE-2023-525727.8 HIGHcifs: Fix UAF in cifs_demultiplex_thread()
CVE-2023-525037.8 HIGHtee: amdtee: fix use-after-free vulnerability in amdtee_close_session
CVE-2023-525177.8 HIGHspi: sun6i: fix race between DMA RX transfer completion and RX FIFO drain
CVE-2023-525237.8 HIGHbpf, sockmap: Reject sk_msg egress redirects to non-TCP sockets
CVE-2023-525137.5 HIGHRDMA/siw: Fix connection failure handling
CVE-2023-525657.1 HIGHmedia: uvcvideo: Fix OOB read
CVE-2023-52562mm/slab_common: fix slab_caches list corruption after kmem_cache_destroy()
CVE-2023-52581netfilter: nf_tables: fix memleak when more than 255 elements expired
CVE-2023-52566nilfs2: fix potential use after free in nilfs_gccache_submit_read_data()
CVE-2023-52564Revert "tty: n_gsm: fix UAF in gsm_cleanup_mux"
CVE-2023-52563drm/meson: fix memory leak on ->hpd_notify callback
CVE-2022-48627vt: fix memory overlapping when deleting chars in the buffer
CVE-2023-52559iommu/vt-d: Avoid memory allocation in iommu_suspend()

Showing 20 of 57 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2023-52508へのコメント

まだコメントはありません


コメントを残す