CVE-2023-52524
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Mar 2, 2024
Updated: Jan 13, 2025
CWE ID 667
Summary
CVE-2023-52524 is a vulnerability affecting the Linux kernel's Near Field Communication (NFC) subsystem. Specifically, in the llcp (Logical Link Control and Adaption Protocol) component, a failure to properly lock the device list during modification can result in list corruption. This issue was identified by the researcher known as syzbot. Unauthorized modifications to the device list could negatively impact system functionality or provide an attacker with unintended access. This vulnerability has been remedied in recent Linux kernel updates.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX