CVE-2023-23005: Null Pointer Dereference
DISPUTED In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the allocmemorytype return value (expects it to be NULL in the error case, whereas it is actually an error pointer). NOTE: this is disputed by third parties because there are no realistic cases in which a user can cause the allocmemorytype error case to be reached.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-23005?
CVE-2023-23005 is a vulnerability in the Linux kernel before version 6.2 that misinterprets the alloc_memory_type return value.
What is the severity of CVE-2023-23005?
The severity of CVE-2023-23005 is medium with a severity value of 5.5.
Which software is affected by CVE-2023-23005?
The Linux kernel versions before 6.2 and SUSE Linux Enterprise Server version 15-sp5 are affected by CVE-2023-23005.
Is there a fix available for CVE-2023-23005?
Yes, a fix is available for CVE-2023-23005. Please refer to the provided references for more information.
Where can I find more information about CVE-2023-23005?
You can find more information about CVE-2023-23005 in the provided references.