UBUNTU-CVE-2023-53721
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-53721
Summary:
Details: In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix a NULL pointer dereference in ath12k_mac_op_hw_scan() In ath12k_mac_op_hw_scan(), the return value of kzalloc() is directly used in memcpy(), which may lead to a NULL pointer dereference on failure of kzalloc(). Fix this bug by adding a check of arg.extraie.ptr. Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.0-03427-QCAHMTSWPL_V1.0_V2.0_SILICONZ-1.15378.4
References: https://ubuntu.com/security/CVE-2023-53721, https://www.cve.org/CVERecord?id=CVE-2023-53721, https://git.kernel.org/linus/8ad314da54c6dd223a6b6cc85019160aa842f659, https://git.kernel.org/stable/c/5a263df398b581189fe632b4ab8440f3dd76c251, https://git.kernel.org/stable/c/8ad314da54c6dd223a6b6cc85019160aa842f659
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
