CVE-2023-7042
Vulnerability Summary
Timeline
Description
A null pointer dereference vulnerability was found in ath10k_wmi_tlv_op_pull_mgmt_tx_compl_ev() in drivers/net/wireless/ath/ath10k/wmi-tlv.c in the Linux kernel. This issue could be exploited to trigger a denial of service.
CVSS Metrics
- v3.1•MEDIUM•Score: 4.4CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.28%• Percentile: 21%
Techniques & Countermeasures
- CWE-476•NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
Affected Systems
- chainguard•hyperv-daemons-generic
< 6.16.6-r0
- chainguard•linux-aws-6.12
< 0
- chainguard•linux-aws-6.18
< 6.18.0-r0
- chainguard•linux-aws-generic
< 6.16.6-r0
- chainguard•linux-aws-generic-boot-installed
< 6.16.6-r0
- chainguard•linux-aws-generic-fips-boot-installed
< 6.16.6-r0
- chainguard•linux-aws-generic-headers
< 6.16.6-r0
- chainguard•linux-aws-generic-modules
< 6.16.6-r0
- chainguard•linux-azure-6.18
< 6.18.2-r0 | < 6.18.7-r0
- chainguard•linux-azure-generic
< 6.18.7-r0 | < 6.16.6-r0
- chainguard•linux-azure-generic-boot-installed
< 6.16.6-r0
- chainguard•linux-azure-generic-fips-boot-installed
< 6.16.6-r0
- chainguard•linux-azure-generic-headers
< 6.16.6-r0
- chainguard•linux-azure-generic-modules
< 6.16.6-r0
- chainguard•linux-gcp-6.18
< 6.18.2-r0
- chainguard•linux-gcp-generic
< 6.16.6-r0 | < 6.18.7-r0
- chainguard•linux-gcp-generic-boot-installed
< 6.16.6-r0
- chainguard•linux-gcp-generic-fips-boot-installed
< 6.16.6-r0
- chainguard•linux-gcp-generic-headers
< 6.16.6-r0
- chainguard•linux-gcp-generic-modules
< 6.16.6-r0
- chainguard•linux-qemu-6.12
< 6.12.67-r0
- chainguard•linux-qemu-6.18
< 6.18.7-r0
- chainguard•linux-qemu-generic
< 6.18.7-r0 | < 6.16.6-r0
- chainguard•linux-qemu-generic-boot-installed
< 6.16.6-r0
- chainguard•linux-qemu-generic-bootc-boot-installed
< 6.18.7-r0 | < 6.16.6-r0
- chainguard•linux-qemu-generic-fips-boot-installed
< 6.16.6-r0
- chainguard•linux-qemu-generic-headers
< 6.16.6-r0
- chainguard•linux-qemu-generic-modules
< 6.16.6-r0
- chainguard•linux-qemu-rc
< 6.17_rc5-r0
- chainguard•linux-qemu-rc-boot-installed
< 6.17_rc5-r0
- chainguard•linux-qemu-rc-fips-boot-installed
< 6.17_rc5-r0
- chainguard•linux-qemu-rc-headers
< 6.17_rc5-r0
- chainguard•linux-qemu-rc-modules
< 6.17_rc5-r0
- chainguard•linux-vmware-6.18
< 6.18.7-r0
- chainguard•linux-vmware-generic
< 6.16.6-r0
- chainguard•linux-vmware-generic-boot-installed
< 6.16.6-r0
- chainguard•linux-vmware-generic-fips-boot-installed
< 6.16.6-r0
- chainguard•linux-vmware-generic-headers
< 6.16.6-r0
- chainguard•linux-vmware-generic-modules
< 6.16.6-r0
- debian•linux
< 5.10.216-1 | < 6.1.82-1 | < 6.7.12-1 | < 6.7.12-1
- ubuntu•linux
< 5.4.0-189.209 | < 5.15.0-112.122 | < 6.8.0-35.35
- ubuntu•linux-allwinner-5.19
all
- ubuntu•linux-aws
< 5.4.0-1128.138 | < 5.15.0-1063.69 | < 6.8.0-1009.9
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
all
- ubuntu•linux-aws-5.15
< 5.15.0-1063.69~20.04.1
- ubuntu•linux-aws-5.19
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.4
< 5.4.0-1128.138~18.04.1
Showing first 50 affected entries in server-rendered view.
References (33)
- https://access.redhat.com/security/cve/CVE-2023-7042
- https://bugzilla.redhat.com/show_bug.cgi?id=2255497
- https://patchwork.kernel.org/project/linux-wireless/patch/20231208043433.271449-1-hdthky0@gmail.com/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/54PLF5J33IRSLSR4UU6LQSMXX6FI5AOQ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C25BK2YH5MZ6VNQXKF2NAJBTGXVEPKGC/
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html
- https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html
- https://ubuntu.com/security/CVE-2023-7042
- https://git.kernel.org/pub/scm/linux/kernel/git/kvalo/ath.git/commit/?h=ath-next&id=ad25ee36f00172f7d53242dc77c69fff7ced0755
- https://lore.kernel.org/all/20231208043433.271449-1-hdthky0@gmail.com/
- https://git.kernel.org/pub/scm/linux/kernel/git/kvalo/ath.git/log/?h=ath-next
- https://www.cve.org/CVERecord?id=CVE-2023-7042
- https://ubuntu.com/security/notices/USN-6816-1
- https://ubuntu.com/security/notices/USN-6817-1
- https://ubuntu.com/security/notices/USN-6820-1
- https://ubuntu.com/security/notices/USN-6821-1
- https://ubuntu.com/security/notices/USN-6821-2
- https://ubuntu.com/security/notices/USN-6817-2
- https://ubuntu.com/security/notices/USN-6828-1
- https://ubuntu.com/security/notices/USN-6820-2
- https://ubuntu.com/security/notices/USN-6821-3
- https://ubuntu.com/security/notices/USN-6817-3
- https://ubuntu.com/security/notices/USN-6821-4
- https://ubuntu.com/security/notices/USN-6871-1
- https://ubuntu.com/security/notices/USN-6878-1
- https://ubuntu.com/security/notices/USN-6892-1
- https://ubuntu.com/security/notices/USN-6896-1
- https://ubuntu.com/security/notices/USN-6896-2
- https://ubuntu.com/security/notices/USN-6896-3
- https://ubuntu.com/security/notices/USN-6896-4
- https://ubuntu.com/security/notices/USN-6896-5
- https://ubuntu.com/security/notices/USN-6919-1
- https://security-tracker.debian.org/tracker/CVE-2023-7042