CVE-2023-52763

In the Linux kernel, the following vulnerability has been resolved: i3c: master: mipi-i3c-hci: Fix a kernel panic for accessing DAT_data. The `i3c_master_bus_init` function may attach the I2C devices before the I3C bus initialization. In this flow, the DAT `alloc_entry`` will be used before the DAT `init`. Additionally, if the `i3c_master_bus_init` fails, the DAT `cleanup` will execute before the device is detached, which will execue DAT `free_entry` function. The above scenario can cause the driver to use DAT_data when it is NULL.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

19 Sep 2025, 14:39

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Linux
Linux linux Kernel
CWE NVD-CWE-noinfo
References () https://git.kernel.org/stable/c/39c71357e68e2f03766f9321b9f4882e49ff1442 - () https://git.kernel.org/stable/c/39c71357e68e2f03766f9321b9f4882e49ff1442 - Patch
References () https://git.kernel.org/stable/c/3cb79a365e7cce8f121bba91312e2ddd206b9781 - () https://git.kernel.org/stable/c/3cb79a365e7cce8f121bba91312e2ddd206b9781 - Patch
References () https://git.kernel.org/stable/c/b53e9758a31c683fc8615df930262192ed5f034b - () https://git.kernel.org/stable/c/b53e9758a31c683fc8615df930262192ed5f034b - Patch
References () https://git.kernel.org/stable/c/e64d23dc65810be4e3395d72df0c398f60c991f9 - () https://git.kernel.org/stable/c/e64d23dc65810be4e3395d72df0c398f60c991f9 - Patch
References () https://git.kernel.org/stable/c/eed74230435c61eeb58abaa275b1820e6a4b7f02 - () https://git.kernel.org/stable/c/eed74230435c61eeb58abaa275b1820e6a4b7f02 - Patch

21 Nov 2024, 08:40

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se resolvió la siguiente vulnerabilidad: i3c: master: mipi-i3c-hci: se corrigió un pánico del kernel al acceder a DAT_data. La función `i3c_master_bus_init` puede conectar los dispositivos I2C antes de la inicialización del bus I3C. En este flujo, el DAT `alloc_entry`` se utilizará antes del DAT `init`. Además, si `i3c_master_bus_init` falla, la `limpieza` de DAT se ejecutará antes de desconectar el dispositivo, lo que ejecutará la función DAT `free_entry`. El escenario anterior puede hacer que el controlador utilice DAT_data cuando es NULL.
References () https://git.kernel.org/stable/c/39c71357e68e2f03766f9321b9f4882e49ff1442 - () https://git.kernel.org/stable/c/39c71357e68e2f03766f9321b9f4882e49ff1442 -
References () https://git.kernel.org/stable/c/3cb79a365e7cce8f121bba91312e2ddd206b9781 - () https://git.kernel.org/stable/c/3cb79a365e7cce8f121bba91312e2ddd206b9781 -
References () https://git.kernel.org/stable/c/b53e9758a31c683fc8615df930262192ed5f034b - () https://git.kernel.org/stable/c/b53e9758a31c683fc8615df930262192ed5f034b -
References () https://git.kernel.org/stable/c/e64d23dc65810be4e3395d72df0c398f60c991f9 - () https://git.kernel.org/stable/c/e64d23dc65810be4e3395d72df0c398f60c991f9 -
References () https://git.kernel.org/stable/c/eed74230435c61eeb58abaa275b1820e6a4b7f02 - () https://git.kernel.org/stable/c/eed74230435c61eeb58abaa275b1820e6a4b7f02 -

21 May 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-21 16:15

Updated : 2025-09-19 14:39


NVD link : CVE-2023-52763

Mitre link : CVE-2023-52763

CVE.ORG link : CVE-2023-52763


JSON object : View

Products Affected

linux

  • linux_kernel