In the Linux kernel, the following vulnerability has been resolved:
i3c: master: mipi-i3c-hci: Fix a kernel panic for accessing DAT_data.
The `i3c_master_bus_init` function may attach the I2C devices before the
I3C bus initialization. In this flow, the DAT `alloc_entry`` will be used
before the DAT `init`. Additionally, if the `i3c_master_bus_init` fails,
the DAT `cleanup` will execute before the device is detached, which will
execue DAT `free_entry` function. The above scenario can cause the driver
to use DAT_data when it is NULL.
Metrics
Affected Vendors & Products
References
History
Mon, 04 Nov 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: Linux
Published: 2024-05-21T15:30:48.369Z
Updated: 2024-11-04T14:52:13.211Z
Reserved: 2024-05-21T15:19:24.238Z
Link: CVE-2023-52763
Vulnrichment
Updated: 2024-08-02T23:11:36.004Z
NVD
Status : Awaiting Analysis
Published: 2024-05-21T16:15:15.630
Modified: 2024-05-21T16:53:56.550
Link: CVE-2023-52763
Redhat