CVE-2023-52607: powerpc/mm: Fix null-pointer dereference in pgtable_cache_add

Description

In the Linux kernel, the following vulnerability has been resolved:

powerpc/mm: Fix null-pointer dereference in pgtable_cache_add

kasprintf() returns a pointer to dynamically allocated memory
which can be NULL upon failure. Ensure the allocation was successful
by checking the pointer validity.

Classification

CVE ID: CVE-2023-52607

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 15.26% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://git.kernel.org/stable/c/21e45a7b08d7cd98d6a53c5fc5111879f2d96611
https://git.kernel.org/stable/c/f6781add1c311c17eff43e14c786004bbacf901e
https://git.kernel.org/stable/c/aa28eecb43cac6e20ef14dfc50b8892c1fbcda5b
https://git.kernel.org/stable/c/ac3ed969a40357b0542d20f096a6d43acdfa6cc7
https://git.kernel.org/stable/c/d482d61025e303a2bef3733a011b6b740215cfa1
https://git.kernel.org/stable/c/145febd85c3bcc5c74d87ef9a598fc7d9122d532
https://git.kernel.org/stable/c/ffd29dc45bc0355393859049f6becddc3ed08f74
https://git.kernel.org/stable/c/f46c8a75263f97bda13c739ba1c90aced0d3b071

Timeline