{"id":"CVE-2023-52469","title":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers/amd/pm: fix a use-after-free in kv_parse_power_table\n\nWhen ps allocated by kzalloc equals to NULL, kv_parse_power_table\nfrees adev->pm.dpm.ps that allocated bef…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers/amd/pm: fix a use-after-free in kv_parse_power_table\n\nWhen ps allocated by kzalloc equals to NULL, kv_parse_power_table\nfrees adev->pm.dpm.ps that allocated bef…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-416"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 4.2.0, < 4.19.306","linux_kernel >= 4.20.0, < 5.4.268","linux_kernel >= 5.5.0, < 5.10.209","linux_kernel >= 5.11.0, < 5.15.148","linux_kernel >= 5.16.0, < 6.1.75","linux_kernel >= 6.2.0, < 6.6.14","linux_kernel >= 6.7.0, < 6.7.2"],"patched":["linux_kernel 6.7.2"],"published":"2024-02-26","updated":"2026-08-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-52469","references":[{"url":"https://git.kernel.org/stable/c/28dd788382c43b330480f57cd34cde0840896743","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3426f059eacc33ecc676b0d66539297e1cfafd02","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/35fa2394d26e919f63600ce631e6aefc95ec2706","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/520e213a0b97b64735a13950e9371e0a5d7a5dc3","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8a27d9d9fc9b5564b8904c3a77a7dea482bfa34e","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8b55b06e737feb2a645b0293ea27e38418876d63","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/95084632a65d5c0d682a83b55935560bdcd2a1e3","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6dcba02ee178282e0d28684d241e0b8462dea6a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/28dd788382c43b330480f57cd34cde0840896743","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/3426f059eacc33ecc676b0d66539297e1cfafd02","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/35fa2394d26e919f63600ce631e6aefc95ec2706","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/520e213a0b97b64735a13950e9371e0a5d7a5dc3","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/8a27d9d9fc9b5564b8904c3a77a7dea482bfa34e","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/8b55b06e737feb2a645b0293ea27e38418876d63","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/95084632a65d5c0d682a83b55935560bdcd2a1e3","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/b6dcba02ee178282e0d28684d241e0b8462dea6a","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00016.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00294,"epssPercentile":0.2223,"ingestedAt":"2026-08-04T10:39:38.016Z","slug":"CVE-2023-52469","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndrivers/amd/pm: fix a use-after-free in kv_parse_power_table\n\nWhen ps allocated by kzalloc equals to NULL, kv_parse_power_table\nfrees adev->pm.dpm.ps that allocated before. However, after the control\nflow goes through the following call chains:\n\nkv_parse_power_table\n  |-> kv_dpm_init\n        |-> kv_dpm_sw_init\n\t      |-> kv_dpm_fini\n\nThe adev->pm.dpm.ps is used in the for loop of kv_dpm_fini after its\nfirst free in kv_parse_power_table and causes a use-after-free bug.\n\n## Affected\n\n- `linux_kernel >= 4.2.0, < 4.19.306`\n- `linux_kernel >= 4.20.0, < 5.4.268`\n- `linux_kernel >= 5.5.0, < 5.10.209`\n- `linux_kernel >= 5.11.0, < 5.15.148`\n- `linux_kernel >= 5.16.0, < 6.1.75`\n- `linux_kernel >= 6.2.0, < 6.6.14`\n- `linux_kernel >= 6.7.0, < 6.7.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 6.7.2`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}