SB20240531334 - NULL pointer dereference in Linux kernel clk mediatek driver
Published: May 31, 2024 Updated: May 14, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2023-52865)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the mtk_topckgen_init(), mtk_infrasys_init_early() and mtk_infrasys_init() functions in drivers/clk/mediatek/clk-mt6797.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/c26feedbc561f2a3cee1a4f717e61bdbdfb4fa92
- https://git.kernel.org/stable/c/4c79cbfb8e9e2311be77182893fda5ea4068c836
- https://git.kernel.org/stable/c/2705c5b97f504e831ae1935c05f0e44f80dfa6b3
- https://git.kernel.org/stable/c/81b16286110728674dcf81137be0687c5055e7bf
- https://git.kernel.org/stable/c/3aefc6fcfbada57fac27f470602d5565e5b76cb4
- https://git.kernel.org/stable/c/357df1c2f6ace96defd557fad709ed1f9f70e16c
- https://git.kernel.org/stable/c/be3f12f16038a558f08fa93cc32fa715746a5235
- https://git.kernel.org/stable/c/122ac6496e4975ddd7ec1edba4f6fc1e15e39478
- https://git.kernel.org/stable/c/606f6366a35a3329545e38129804d65ef26ed7d2
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.330
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.299
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.201
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.139
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.261
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.63
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.5.12
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.2
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.7