#VU91353 Information disclosure in Linux kernel - CVE-2023-52652
Published: June 8, 2024 / Updated: May 13, 2025
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to information disclosure within the pci_vntb_probe() function in drivers/pci/endpoint/functions/pci-epf-vntb.c, within the EXPORT_SYMBOL() and ntb_register_device() functions in drivers/ntb/core.c. A local user can gain access to sensitive information.
Remediation
External links
- https://git.kernel.org/stable/c/a62b9f3d7bbfac874cc0c638bc1776dcf1f8ec06
- https://git.kernel.org/stable/c/6632a54ac8057cc0b0d789c6f73883e871bcd25c
- https://git.kernel.org/stable/c/a039690d323221eb5865f1f31db3ec264e7a14b6
- https://git.kernel.org/stable/c/e8025439ef8e16029dc313d78a351ef192469b7b
- https://git.kernel.org/stable/c/913421f9f7fd8324dcc41753d0f28b52e177ef04
- https://git.kernel.org/stable/c/aebfdfe39b9327a3077d0df8db3beb3160c9bdd0
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.153
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.83
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.23
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.7.11
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.8.2