CVE-2023-52500

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Mar 2, 2024
Updated: Jan 13, 2025

Summary

CVE-2023-52500 is a vulnerability affecting the Linux kernel. It involves the pm80xx driver in the SCSI subsystem. The issue arises from a failure to free tags allocated for the OPC_INB_SET_CONTROLLER_CONFIG command when a response is received. This could potentially lead to memory leaks and consuming system resources, posing a risk to the stability and security of the affected system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share