VDB

CISA-2023-52893

CISA-2023-52893 PUBLISHED

Reported by Linux · Published August 21, 2024

In the Linux kernel, the following vulnerability has been resolved: gsmi: fix null-deref in gsmi_get_variable We can get EFI variables without fetching the attribute, so we must allow for that in gsmi. commit 859748255b43 ("efi: pstore: Omit efivars caching EFI varstore access layer") added a new get_variable call with attr=NULL, which triggers panic in gsmi.

Affected Products

VendorProductVersions
LinuxLinux74c5b31c6618f01079212332b2e5f6c42f2d6307, 74c5b31c6618f01079212332b2e5f6c42f2d6307, 74c5b31c6618f01079212332b2e5f6c42f2d6307
LinuxLinux3.0, 0, 4.14.304
LinuxLinux74c5b31c6618f01079212332b2e5f6c42f2d6307, 74c5b31c6618f01079212332b2e5f6c42f2d6307, *

Timeline

  • Aug 21, 2024 CVE Published
  • Dec 19, 2024 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›