CVE-2023-3355
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2023-3355 is a newly discovered vulnerability affecting the Linux kernel's drivers/gpu/drm/msm/msm_gem_submit.c file. The issue lies in the submit_lookup_cmds function, where a NULL pointer dereference occurs due to the lack of a check on the return value of kmalloc(). This flaw enables a local user to cause a system crash. By exploiting this vulnerability, an attacker can potentially gain unintended control over the system's execution flow, potentially leading to more severe consequences. This vulnerability poses a significant security risk, as it can be exploited locally without requiring elevated privileges. System administrators are advised to apply the necessary patches promptly to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Advisories, Assessments, and Mitigations
Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future
- Gain complete coverage of your cyber, third party, and physical attack surface
- Proactively mitigate threats before they turn into costly attacks
- Make fast, effective, data-driven decisions