CVE-2023-52524

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 2, 2024
Updated: Jan 13, 2025
CWE ID 667

Summary

CVE-2023-52524 is a vulnerability affecting the Linux kernel's Near Field Communication (NFC) subsystem. Specifically, in the llcp (Logical Link Control and Adaption Protocol) component, a failure to properly lock the device list during modification can result in list corruption. This issue was identified by the researcher known as syzbot. Unauthorized modifications to the device list could negatively impact system functionality or provide an attacker with unintended access. This vulnerability has been remedied in recent Linux kernel updates.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share