First published: Wed Mar 01 2023(Updated: )
** DISPUTED ** In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case, whereas it is actually an error pointer). NOTE: this is disputed by third parties because there are no realistic cases in which a user can cause the alloc_memory_type error case to be reached.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | <6.2 | |
SUSE Linux Enterprise Server | =15-sp5 | |
<6.2 | ||
=15-sp5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23005 is a vulnerability in the Linux kernel before version 6.2 that misinterprets the alloc_memory_type return value.
The severity of CVE-2023-23005 is medium with a severity value of 5.5.
The Linux kernel versions before 6.2 and SUSE Linux Enterprise Server version 15-sp5 are affected by CVE-2023-23005.
Yes, a fix is available for CVE-2023-23005. Please refer to the provided references for more information.
You can find more information about CVE-2023-23005 in the provided references.