CVE-2023-6679: Kernel: null pointer dereference in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.c
A null pointer dereference vulnerability was found in dpllpinparentpinset() in drivers/dpll/dpllnetlink.c in Digital Phase Locked Loop (DPLL) subsystem in the Linux kernel, which could be exploited to trigger denial of service.
Refer: https://lore.kernel.org/netdev/20231211083758.1082853-1-jiri@resnulli.us/
Other sources
A null pointer dereference vulnerability was found in dpllpinparentpinset() in drivers/dpll/dpllnetlink.c in the Digital Phase Locked Loop (DPLL) subsystem in the Linux kernel. This issue could be exploited to trigger a denial of service.
— NVD
Linux Kernel is vulnerable to a denial of service, caused by a NULL pointer dereference flaw in the dpllpinparentpinset() function in drivers/dpll/dpllnetlink.c in the Digital Phase Locked Loop (DPLL) subsystem. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6679?
CVE-2023-6679 has a severity rating that indicates a potential denial of service risk due to a null pointer dereference vulnerability.
How do I fix CVE-2023-6679?
To fix CVE-2023-6679, update to the latest version of the Linux Kernel or applicable distributions that have patched this vulnerability.
Which software versions are affected by CVE-2023-6679?
CVE-2023-6679 affects the Linux Kernel, Fedora 38, Red Hat Enterprise Linux 9.0, and IBM InfoSphere Guardium up to version 12.0.
What could be the impact of exploiting CVE-2023-6679?
Exploiting CVE-2023-6679 could lead to a denial of service, causing affected systems to become unresponsive.
Is there a workaround for CVE-2023-6679?
Currently, the best resolution for CVE-2023-6679 is to apply the latest updates or patches provided by your Linux distribution.