CVE-2023-52614

Updated: 2024-12-13 00:23:02.979565

Description:

In the Linux kernel, the following vulnerability has been resolved: PM / devfreq: Fix buffer overflow in trans_stat_show Fix buffer overflow in trans_stat_show(). Convert simple snprintf to the more secure scnprintf with size of PAGE_SIZE. Add condition checking if we are exceeding PAGE_SIZE and exit early from loop. Also add at the end a warning that we exceeded PAGE_SIZE and that stats is disabled. Return -EFBIG in the case where we don't have enough space to write the full transition table. Also document in the ABI that this function can return -EFBIG error.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.8 HIGH Released CLSA-2025:1738671431 2025-02-05 02:21:48
AlmaLinux 9.2 FIPS kernel 5.14.0 7.8 HIGH Released CLSA-2025:1738670922 2025-02-05 02:57:33
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Not Vulnerable 2025-01-10 00:58:34
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Not Vulnerable 2025-01-17 01:24:40
Ubuntu 16.04 ELS linux 4.4.0 7.8 HIGH Released CLSA-2024:1733142550 2025-02-07 06:40:17
Ubuntu 16.04 ELS linux-hwe 4.15.0 7.8 HIGH Released CLSA-2024:1733484110 2025-02-07 06:40:18
Ubuntu 18.04 ELS linux 4.15.0 7.8 HIGH Released CLSA-2024:1733483766 2025-02-07 06:40:22