Buffer Overflow Vulnerability in Linux Kernel Affecting Intel Graphics
CVE-2023-53678
What is CVE-2023-53678?
A vulnerability in the Intel Graphics Driver within the Linux kernel can lead to a buffer overflow during system suspend operations. Specifically, if the framebuffer device (fbdev) is not initialized, an attempt to suspend can cause a NULL pointer dereference, potentially affecting system stability and performance. This issue occurs on platforms without an active display, where the fbdev suspend function should be bypassed. A patch has been introduced to ensure that suspending fbdev is contingent upon the display's presence, effectively mitigating the risk of system crashes and unexpected behavior.
Affected Version(s)
Linux f8cc091e05305231c8f747ca253a90ff0cea60b9 < 27b5871abd5cc068c549fd23062c82e257fc0b9c
Linux f8cc091e05305231c8f747ca253a90ff0cea60b9 < 8ed572d5a0f1509e691a75a0e3d3588050371f1e
Linux f8cc091e05305231c8f747ca253a90ff0cea60b9 < 8038510b1fe443ffbc0e356db5f47cbb8678a594