CVE-2023-52708 Information

Description

In the Linux kernel the following vulnerability has been resolved:

mmc: mmc_spi: fix error handling in mmc_spi_probe()

If mmc_add_host() fails it doesn’t need to call mmc_remove_host() or it will cause null-ptr-deref because of deleting a not added device in mmc_remove_host().

To fix this goto label ‘fail_glue_init’ if mmc_add_host() fails and change the label ‘fail_add_host’ to ‘fail_gpiod_request’.

Reference

https://git.kernel.org/stable/c/e9b488d60f51ae312006e224e03a30a151c28bdd https://git.kernel.org/stable/c/0b3edcb24bd81b3b2e3dac89f4733bfd47d283be https://git.kernel.org/stable/c/ecad2fafd424ffdc203b2748ded0b37e4bbecef3 https://git.kernel.org/stable/c/82645bf4ed02abe930a659c5fe16d593a6dbd93f https://git.kernel.org/stable/c/cf4c9d2ac1e42c7d18b921bec39486896645b714

Share on: