CVE-2023-28328: Null Pointer Dereference
A NULL pointer dereference flaw was found in the az6027 driver in drivers/media/usb/dev-usb/az6027.c in the Linux Kernel. The message from user space is not checked properly before transferring into the device. This flaw allows a local user to crash the system or potentially cause a denial of service.
Other sources
A null pointer dereference issue was found in the az6027 driver in drivers/media/usb/dev-usb/az6027.c in the Linux Kernel. The message from user space is not checked properly before transferring into the device. A local user could use this flaw to crash the system or potentially cause a denial of service.
Reference: https://lore.kernel.org/linux-media/20221120065918.2160782-1-zhongbaisong@huawei.com/ https://lore.kernel.org/lkml/CAO4mrfcPHB5aQJO=mpqV+p8mPLNg-Fok0gw8gZ=zemAfMGTzMg@mail.gmail.com/
— Red Hat
Linux Kernel is vulnerable to a denial of service, caused by a NULL pointer dereference flaw in the az6027 driver in drivers/media/usb/dev-usb/az6027.c. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause the system to crash.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28328?
CVE-2023-28328 has a high severity rating due to its potential to cause system crashes and denial of service.
What impact does CVE-2023-28328 have on affected systems?
CVE-2023-28328 can lead to local users crashing the system, resulting in a denial of service.
How do I mitigate CVE-2023-28328?
To mitigate CVE-2023-28328, users should upgrade to kernel versions 6.2 or apply the recommended patches.
Which systems are affected by CVE-2023-28328?
CVE-2023-28328 affects systems running vulnerable versions of the Linux Kernel and certain IBM Security Verify Governance components.
Is there a way to check if my system is vulnerable to CVE-2023-28328?
You can check your system's kernel version and compare it to the vulnerable versions noted in the CVE-2023-28328 documentation.