CVE-2023-3355

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jun 28, 2023
Updated: Nov 7, 2023
CWE ID 476

Summary

CVE-2023-3355 is a newly discovered vulnerability affecting the Linux kernel's drivers/gpu/drm/msm/msm_gem_submit.c file. The issue lies in the submit_lookup_cmds function, where a NULL pointer dereference occurs due to the lack of a check on the return value of kmalloc(). This flaw enables a local user to cause a system crash. By exploiting this vulnerability, an attacker can potentially gain unintended control over the system's execution flow, potentially leading to more severe consequences. This vulnerability poses a significant security risk, as it can be exploited locally without requiring elevated privileges. System administrators are advised to apply the necessary patches promptly to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2023-3355 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions