CVE-2023-28328

ECS: NULL Pointer Dereference (CVE-2023-28328)

Affected

  • Dell/ECS 3.8.1.0..*

Description

A NULL pointer dereference flaw was found in the az6027 driver in drivers/media/usb/dev-usb/az6027.c in the Linux Kernel. The message from user space is not checked properly before transferring into the device. This flaw allows a local user to crash the system or potentially cause a denial of service.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

DellECS
3.8.1.0

Metrics

11.7 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
none
no public PoC known
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2023-04-19 00:00 UTC
CWE-476

Weakness classes (CWE)

  • CWE-476Base

    NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

    cwe.mitre.org →

References & sources