CVE-2023-52789 Affecting cluster-md-kmp-default package, versions <6.4.0-150600.23.14.2
Threat Intelligence
EPSS
0.04% (14th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-SLES156-CLUSTERMDKMPDEFAULT-7549359
- published 23 Jul 2024
- disclosed 22 Jul 2024
Introduced: 22 Jul 2024
CVE-2023-52789 Open this link in a new tabHow to fix?
Upgrade SLES:15.6
cluster-md-kmp-default
to version 6.4.0-150600.23.14.2 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream cluster-md-kmp-default
package and not the cluster-md-kmp-default
package as distributed by SLES
.
See How to fix?
for SLES:15.6
relevant fixed versions and status.
In the Linux kernel, the following vulnerability has been resolved:
tty: vcc: Add check for kstrdup() in vcc_probe()
Add check for the return value of kstrdup() and return the error, if it fails in order to avoid NULL pointer dereference.
References
- https://www.suse.com/security/cve/CVE-2023-52789.html
- https://bugzilla.suse.com/1225180
- https://git.kernel.org/stable/c/38cd56fc9de78bf3c878790785e8c231116ef9d3
- https://git.kernel.org/stable/c/460284dfb10b207980c6f3f7046e33446ceb38ac
- https://git.kernel.org/stable/c/4a24a31826246b15477399febd13292b0c9f0ee9
- https://git.kernel.org/stable/c/4ef41a7f33ffe1a335e7db7e1564ddc6afad47cc
- https://git.kernel.org/stable/c/6c80f48912b5bd4965352d1a9a989e21743a4a06
- https://git.kernel.org/stable/c/7cebc86481bf16049e266f6774d90f2fd4f8d5d2
- https://git.kernel.org/stable/c/8f8771757b130383732195497e47fba2aba76d3a
- https://git.kernel.org/stable/c/909963e0c16778cec28efb1affc21558825f4200
- https://git.kernel.org/stable/c/d81ffb87aaa75f842cd7aa57091810353755b3e6
CVSS Scores
version 3.1