CVE-2023-52641: fs/ntfs3: Add NULL ptr dereference checking at the end of attr_allocate_frame()

Description

In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: Add NULL ptr dereference checking at the end of attr_allocate_frame()

It is preferable to exit through the out: label because
internal debugging functions are located there.

Classification

CVE ID: CVE-2023-52641

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 5.06% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://git.kernel.org/stable/c/ee8db6475cb15c8122855f72ad4cfa5375af6a7b
https://git.kernel.org/stable/c/50545eb6cd5f7ff852a01fa29b7372524ef948cc
https://git.kernel.org/stable/c/947c3f3d31ea185ddc8e7f198873f17d36deb24c
https://git.kernel.org/stable/c/847b68f58c212f0439c5a8101b3841f32caffccd
https://git.kernel.org/stable/c/aaab47f204aaf47838241d57bf8662c8840de60a

Timeline