Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Fix potential null-ptr-deref in pass_establish() If get_ep_from_tid() fails to lookup non-NULL value for ep, ep is dereferenced later regardless of whether it is empty. This patch adds a simple sanity check to fix the issue. Found by Linux Verification Center (linuxtesting.org) with SVACE.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.7, < 5.15.99 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/283861a4c52c1ea4df3dd1b6fc75a50796ce3524Patch
- https://git.kernel.org/stable/c/2cfc00e974d75a3aa8155f2660f57d342e1f67caPatch
- https://git.kernel.org/stable/c/9dca64042d855a24b0bd81ce242e5dc7e939f6ebPatch
- https://git.kernel.org/stable/c/9ddc77eefb2a567b705c3c86ab2ddabe43cadf1bPatch
FAQ
What is CVE-2023-53335?
CVE-2023-53335 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Fix potential null-ptr-deref in pass_establish() If get_ep_from_tid() fails to lookup non-NULL value for ep, ep is der...
How severe is CVE-2023-53335?
CVE-2023-53335 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-53335?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.