CVE-2023-52631

Analyzed
Published: 02 Apr 2024, 06:22
Last modified:11 May 2026, 19:30

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (cve.org)
EPSS Score
0.02% LOW
0% probability -0.01%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

02 Apr 2024, 06:22
Published
Vulnerability first disclosed
11 May 2026, 19:30
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix an NULL dereference bug The issue here is when this is called from ntfs_load_attr_list(). The "size" comes from le32_to_cpu(attr->res.data_size) so it can't overflow on a 64bit systems but on 32bit systems the "+ 1023" can overflow and the result is zero. This means that the kmalloc will succeed by returning the ZERO_SIZE_PTR and then the memcpy() will crash with an Oops on the next line.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.02% Percentile: 4%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • linuxlinux

    ≥ be71b5cba2e6485e8959da7a9f9a44461a1bb074, < ae4acad41b0f93f1c26cc0fc9135bb79d8282d0b | ≥ be71b5cba2e6485e8959da7a9f9a44461a1bb074, < ec1bedd797588fe38fc11cba26d77bb1d9b194c6 | ≥ be71b5cba2e6485e8959da7a9f9a44461a1bb074, < fb7bcd1722bc9bc55160378f5f99c01198fd14a7 | ≥ be71b5cba2e6485e8959da7a9f9a44461a1bb074, < 686820fe141ea0220fc6fdfc7e5694f915cf64b2 | ≥ be71b5cba2e6485e8959da7a9f9a44461a1bb074, < b2dd7b953c25ffd5912dda17e980e7168bebcf6c | 5.15

  • linuxlinux_kernel

    ≥ 5.15, < 5.15.149 | ≥ 5.16, < 6.1.78 | ≥ 6.2, < 6.6.17 | ≥ 6.7, < 6.7.5 | 6.8:rc1 | 6.8:rc2 | 6.8:rc3

References (5)