SB20240711198 - Input validation error in Linux kernel tty serial driver
Published: July 11, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2023-52488)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the sc16is7xx_fifo_read(), sc16is7xx_fifo_write() and sc16is7xx_regmap_precious() functions in drivers/tty/serial/sc16is7xx.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/416b10d2817c94db86829fb92ad43ce7d002c573
- https://git.kernel.org/stable/c/084c24e788d9cf29c55564de368bf5284f2bb5db
- https://git.kernel.org/stable/c/aa7cb4787698add9367b19f7afc667662c9bdb23
- https://git.kernel.org/stable/c/dbf4ab821804df071c8b566d9813083125e6d97b
- https://git.kernel.org/stable/c/e635f652696ef6f1230621cfd89c350cb5ec6169
- https://git.kernel.org/stable/c/4e37416e4ee1b1bc17364a68973e0c63be89e611
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.215