In the Linux kernel, the following vulnerability has been resolved:
genirq/ipi: Fix NULL pointer deref in irq_data_get_affinity_mask()
If ipi_send_{mask|single}() is called with an invalid interrupt number, all
the local variables there will be NULL. ipi_send_verify() which is invoked
from these functions does verify its 'data' parameter, resulting in a
kernel oops in irq_data_get_affinity_mask() as the passed NULL pointer gets
dereferenced.
Add a missing NULL pointer check in ipi_send_verify()...
Found by Linux Verification Center (linuxtesting.org) with the SVACE static
analysis tool.
References
Configurations
Configuration 1 (hide)
|
History
10 Dec 2025, 18:43
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://git.kernel.org/stable/c/7448c73d64075051f50caed2c62f46553b69ab8a - Patch | |
| References | () https://git.kernel.org/stable/c/926aef60ea64cd9becf2829f7388f48dbe8bcb11 - Patch | |
| References | () https://git.kernel.org/stable/c/feabecaff5902f896531dde90646ca5dfa9d4f7d - Patch | |
| First Time |
Linux
Linux linux Kernel |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
| CWE | CWE-476 | |
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
16 Sep 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-09-16 17:15
Updated : 2025-12-10 18:43
NVD link : CVE-2023-53332
Mitre link : CVE-2023-53332
CVE.ORG link : CVE-2023-53332
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-476
NULL Pointer Dereference
