In the Linux kernel, the following vulnerability has been resolved:
drivers/amd/pm: fix a use-after-free in kv_parse_power_table
When ps allocated by kzalloc equals to NULL, kv_parse_power_table
frees adev->pm.dpm.ps that allocated before. However, after the control
flow goes through the following call chains:
kv_parse_power_table
|-> kv_dpm_init
|-> kv_dpm_sw_init
|-> kv_dpm_fini
The adev->pm.dpm.ps is used in the for loop of kv_dpm_fini after its
first free in kv_parse_power_table and causes a use-after-free bug.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Linux
Published: 2024-02-25T08:16:33.016Z
Updated: 2024-05-28T19:50:00.874Z
Reserved: 2024-02-20T12:30:33.297Z
Link: CVE-2023-52469
JSON object: View
NVD Information
Status : Modified
Published: 2024-02-26T16:27:48.767
Modified: 2024-06-27T13:15:53.007
Link: CVE-2023-52469
JSON object: View
Redhat Information
No data.
CWE