CVE-2023-52449: mtd: Fix gluebi NULL pointer dereference caused by ftl notifier

Published Feb 22, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

mtd: Fix gluebi NULL pointer dereference caused by ftl notifier

If both ftl.ko and gluebi.ko are loaded, the notifier of ftl triggers NULL pointer dereference when trying to access ‘gluebi->desc’ in gluebiread().

ubigluebiinit ubiregistervolumenotifier ubienumeratevolumes ubinotifyall gluebinotify nb->notifiercall() gluebicreate mtddeviceregister mtddeviceparseregister addmtddevice blktransnotifyadd not->add() ftladdmtd tr->addmtd() scanheader mtdread mtdreadoob mtdreadoobstd gluebiread mtd->read() gluebi->desc - NULL

Detailed reproduction information available at the Link [1],

In the normal case, obtain gluebi->desc in the gluebigetdevice(), and access gluebi->desc in the gluebiread(). However, gluebigetdevice() is not executed in advance in the ftladdmtd() process, which leads to NULL pointer dereference.

The solution for the gluebi module is to run jffs2 on the UBI volume without considering working with ftl or mtdblock [2]. Therefore, this problem can be avoided by preventing gluebi from creating the mtdblock device after creating mtd partition of the type MTDUBIVOLUME.

Affected Software

8 affected componentsFixes available
Linux Linux kernel>=2.6.31<4.19.306
Linux Linux kernel>=4.20<5.4.268
Linux Linux kernel>=5.5.0<5.10.209
Linux Linux kernel>=5.11.0<5.15.148
Linux Linux kernel>=5.16.0<6.1.75
Linux Linux kernel>=6.2.0<6.6.14
Linux Linux kernel>=6.7.0<6.7.2
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1

Event History

Feb 22, 2024
CVE Published
via MITRE·04:21 PM
Data Sourced
via MITRE·04:21 PM
Description
Mar 11, 2024
Data Sourced
via Launchpad·09:51 PM
Description
Apr 27, 2025
Data Sourced
via Ubuntu·11:16 PM
RemedyDescriptionSeverityAffected Software
May 9, 2025
Data Sourced
via Debian·11:19 PM
DescriptionAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2023-52449?

CVE-2023-52449 is classified as a potential high-severity vulnerability due to the risk of a NULL pointer dereference in the Linux kernel.

2

How do I fix CVE-2023-52449?

To mitigate CVE-2023-52449, update the Linux kernel to one of the patched versions listed in the vulnerability report.

3

What impact does CVE-2023-52449 have on my system?

CVE-2023-52449 may lead to a crash or denial of service on systems where both ftl.ko and gluebi.ko modules are loaded.

4

Which Linux kernel versions are affected by CVE-2023-52449?

CVE-2023-52449 affects specific Linux kernel versions between 2.6.31 to 6.12.10.

5

Is my system safe from CVE-2023-52449 if I am not using ftl.ko and gluebi.ko?

If ftl.ko and gluebi.ko are not loaded, your system may be less exposed, but it is advisable to apply security updates regardless.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203