SB2024070831 - NULL pointer dereference in Linux kernel fs
Published: July 8, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2023-52646)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the aio_ring_mremap() function in fs/aio.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/808f1e4b5723ae4eda724d2ad6f6638905eefd95
- https://git.kernel.org/stable/c/d8dca1bfe9adcae38b35add64977818c0c13dd22
- https://git.kernel.org/stable/c/4326d0080f7e84fba775da41d158f46cf9d3f1c2
- https://git.kernel.org/stable/c/c261f798f7baa8080cf0214081d43d5f86bb073f
- https://git.kernel.org/stable/c/178993157e8c50aef7f35d7d6d3b44bb428199e1
- https://git.kernel.org/stable/c/af126acf01a12bdb04986fd26fc2eb3b40249e0d
- https://git.kernel.org/stable/c/81e9d6f8647650a7bead74c5f926e29970e834d1
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.306
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.273
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.169
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.95
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.232
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.13
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2