目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2023-52627— Linux kernel 安全漏洞

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于空指针取消引用。

AI 预测 7.8 利用难度: 困难 EPSS 0.23% · P12

可能的 ATT&CK 技术 1 AI

T1205.001 · Port Knocking

影响版本矩阵 14

厂商产品 版本范围状态
Linux Linux ca69300173b642ba64118200172171ea5967b6c5< 1eba6f7ffa295a0eec098c107043074be7cc4ec5 affected
ca69300173b642ba64118200172171ea5967b6c5< 49f322ce1f265935f15e5512da69a399f27a5091 affected
ca69300173b642ba64118200172171ea5967b6c5< 137568aa540a9f587c48ff7d4c51cdba08cfe9a4 affected
ca69300173b642ba64118200172171ea5967b6c5< 89c4e63324e208a23098f7fb15c00487cecbfed2 affected
ca69300173b642ba64118200172171ea5967b6c5< 55aca2ce91a63740278502066beaddbd841af9c6 affected
ca69300173b642ba64118200172171ea5967b6c5< 020e71c7ffc25dfe29ed9be6c2d39af7bd7f661f affected
5.6 affected
< 5.6 unaffected
… +6 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2023-52627 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
iio: adc: ad7091r: Allow users to configure device events
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7091r: Allow users to configure device events AD7091R-5 devices are supported by the ad7091r-5 driver together with the ad7091r-base driver. Those drivers declared iio events for notifying user space when ADC readings fall bellow the thresholds of low limit registers or above the values set in high limit registers. However, to configure iio events and their thresholds, a set of callback functions must be implemented and those were not present until now. The consequence of trying to configure ad7091r-5 events without the proper callback functions was a null pointer dereference in the kernel because the pointers to the callback functions were not set. Implement event configuration callbacks allowing users to read/write event thresholds and enable/disable event generation. Since the event spec structs are generic to AD7091R devices, also move those from the ad7091r-5 driver the base driver so they can be reused when support for ad7091r-2/-4/-8 be added.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于空指针取消引用。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux ca69300173b642ba64118200172171ea5967b6c5 ~ 1eba6f7ffa295a0eec098c107043074be7cc4ec5 -
Linux Linux 5.6 -

二、漏洞 CVE-2023-52627 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2023-52627 的情报信息

请登录查看更多情报信息。

CVE-2023-52627 邮件列表归档 (1)

CVE-2023-52627 其他参考 (6)

同批安全公告 · Linux · 2024-03-26 · 共 13 条

CVE-2023-52623 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-26646 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-26644 Linux kernel 安全漏洞
CVE-2024-26645 Linux kernel 安全漏洞
CVE-2023-52621 Linux kernel 安全漏洞
CVE-2023-52622 Linux kernel 安全漏洞
CVE-2023-52624 Linux kernel 安全漏洞
CVE-2023-52625 Linux kernel 安全漏洞
CVE-2023-52626 Linux kernel 安全漏洞
CVE-2024-26647 Linux kernel 安全漏洞
CVE-2024-26648 Linux kernel 安全漏洞
CVE-2024-26649 Linux kernel 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2023-52627

暂无评论


发表评论