CVE-2023-52502

Source
https://cve.org/CVERecord?id=CVE-2023-52502
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-52502.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-52502
Downstream
Related
Published
2024-03-02T21:52:17.218Z
Modified
2026-04-11T12:46:31.553053Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
net: nfc: fix races in nfc_llcp_sock_get() and nfc_llcp_sock_get_sn()
Details

In the Linux kernel, the following vulnerability has been resolved:

net: nfc: fix races in nfcllcpsockget() and nfcllcpsockget_sn()

Sili Luo reported a race in nfcllcpsock_get(), leading to UAF.

Getting a reference on the socket found in a lookup while holding a lock should happen before releasing the lock.

nfcllcpsockgetsn() has a similar problem.

Finally nfcllcprecvsnl() needs to make sure the socket found by nfcllcpsockfrom_sn() does not disappear.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/52xxx/CVE-2023-52502.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8f50020ed9b81ba909ce9573f9d05263cdebf502
Fixed
e863f5720a5680e50c4cecf12424d7cc31b3eb0a
Fixed
7adcf014bda16cdbf804af5c164d94d5d025db2d
Fixed
6ac22ecdaad2ecc662048f8c6b0ceb1ca0699ef9
Fixed
d888d3f70b0de32b4f51534175f039ddab15eef8
Fixed
e4f2611f07c87b3ddb57c4b9e8efcd1e330fc3dc
Fixed
d1af8a39cf839d93c8967fdd858f6bbdc3e4a15c
Fixed
31c07dffafce914c1d1543c135382a11ff058d93

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-52502.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.6.0
Fixed
4.19.297
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.259
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.199
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.136
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.59
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.5.8

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-52502.json"