CVE-2023-3357: Null Pointer Dereference
Published Jun 28, 2023
·Updated
A NULL pointer dereference flaw was found in the Linux kernel AMD Sensor Fusion Hub driver. This flaw allows a local user to crash the system.
Affected Software
8 affected components
Linux Linux kernel<=6.0.19
Linux Linux kernel=6.1-rc1
Linux Linux kernel=6.1-rc2
Linux Linux kernel=6.1-rc3
Linux Linux kernel=6.1-rc4
Linux Linux kernel=6.1-rc5
Linux Linux kernel=6.1-rc6
Linux Linux kernel=6.1-rc7
Remediation
Event History
Jun 28, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Who can exploit this issue?
A local user with low privileges can trigger the flaw. The provided CVSS vector indicates local access is required and no user interaction is needed.
2
What is the impact of successful exploitation?
Successful exploitation can crash the affected system, causing a denial of service. The supplied CVSS vector indicates availability impact only, with no stated confidentiality or integrity impact.
3
Is a fix available?
Yes. A patch is available, and the referenced Linux kernel commit is 53ffa6a9f83b2170c60591da1ead8791d5a42e81.