CVE-2023-52858 Affecting dlm-kmp-default package, versions <6.4.0-150600.23.14.2
Threat Intelligence
EPSS
0.04% (12th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-SLES156-DLMKMPDEFAULT-7550601
- published 23 Jul 2024
- disclosed 22 Jul 2024
Introduced: 22 Jul 2024
CVE-2023-52858 Open this link in a new tabHow to fix?
Upgrade SLES:15.6
dlm-kmp-default
to version 6.4.0-150600.23.14.2 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream dlm-kmp-default
package and not the dlm-kmp-default
package as distributed by SLES
.
See How to fix?
for SLES:15.6
relevant fixed versions and status.
In the Linux kernel, the following vulnerability has been resolved:
clk: mediatek: clk-mt7629: Add check for mtk_alloc_clk_data
Add the check for the return value of mtk_alloc_clk_data() in order to avoid NULL pointer dereference.
References
- https://www.suse.com/security/cve/CVE-2023-52858.html
- https://bugzilla.suse.com/1225566
- https://git.kernel.org/stable/c/1d89430fc3158f872d492f1b88d07262f48290c0
- https://git.kernel.org/stable/c/2befa515c1bb6cdd33c262b909d93d1973a219aa
- https://git.kernel.org/stable/c/4f861b63945e076f9f003a5fad958174096df1ee
- https://git.kernel.org/stable/c/5fbea47eebff5daeca7d918c99289bcd3ae4dc8d
- https://git.kernel.org/stable/c/a836efc21ef04608333d6d05753e558ebd1f85d0
- https://git.kernel.org/stable/c/e8ae4b49dd9cfde69d8de8c0c0cd7cf1b004482e
- https://git.kernel.org/stable/c/e964d21dc034b650d719c4ea39564bec72b42f94
CVSS Scores
version 3.1