Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: of: Fix double free in of_parse_phandle_with_args_map In of_parse_phandle_with_args_map() the inner loop that iterates through the map entries calls of_node_put(new) to free the reference acquired by the previous iteration of the inner loop. This assumes that the value of "new" is NULL on the first iteration of the inner loop. Make sure that this is true in all iterations of the outer loop by setting "new" to NULL after its value is assigned to "cur". Extend the unittest to detect the double free and add an additional test case that actually triggers this path.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.17, < 4.19.306 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/26b4d702c44f9e5cf3c5c001ae619a4a001889dbPatch
- https://git.kernel.org/stable/c/4541004084527ce9e95a818ebbc4e6b293ffca21Patch
- https://git.kernel.org/stable/c/4dde83569832f9377362e50f7748463340c5db6bPatch
- https://git.kernel.org/stable/c/a0a061151a6200c13149dbcdb6c065203c8425d2Patch
- https://git.kernel.org/stable/c/b64d09a4e8596f76d27f4b4a90a1cf6baf6a82f8Patch
- https://git.kernel.org/stable/c/b9d760dae5b10e73369b769073525acd7b3be2bdPatch
- https://git.kernel.org/stable/c/cafa992134124e785609a406da4ff2b54052aff7Patch
- https://git.kernel.org/stable/c/d5f490343c77e6708b6c4aa7dbbfbcbb9546adeaPatch
- https://git.kernel.org/stable/c/26b4d702c44f9e5cf3c5c001ae619a4a001889dbPatch
- https://git.kernel.org/stable/c/4541004084527ce9e95a818ebbc4e6b293ffca21Patch
- https://git.kernel.org/stable/c/4dde83569832f9377362e50f7748463340c5db6bPatch
- https://git.kernel.org/stable/c/a0a061151a6200c13149dbcdb6c065203c8425d2Patch
- https://git.kernel.org/stable/c/b64d09a4e8596f76d27f4b4a90a1cf6baf6a82f8Patch
- https://git.kernel.org/stable/c/b9d760dae5b10e73369b769073525acd7b3be2bdPatch
- https://git.kernel.org/stable/c/cafa992134124e785609a406da4ff2b54052aff7Patch
FAQ
What is CVE-2023-52679?
CVE-2023-52679 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: of: Fix double free in of_parse_phandle_with_args_map In of_parse_phandle_with_args_map() the inner loop that iterates through the...
How severe is CVE-2023-52679?
CVE-2023-52679 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-52679?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux.