Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-52607

17
FAUCET Score

CVE-2023-52607 is a null-pointer dereference vulnerability in the Linux kernel's powerpc/mm component, specifically within the pgtable_cache_add function. This flaw arises when kasprintf() fails to allocate memory, returning a NULL pointer that is not properly checked, leading to a system crash. Rated with a CVSS score of 5.5 (Medium), this vulnerability can be exploited locally with low attack complexity, resulting in a high impact on system availability (denial of service). There is no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, nor are there any public exploit modules available on platforms like Metasploit or ExploitDB. The vulnerability has received minimal community discussion and media coverage, indicating a low level of public awareness.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.19.307CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, <= 5.4.269CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, <= 5.10.210CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, <= 5.15.149CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.77CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.23%
Probability of exploitation in next 30 days
EPSS Percentile
14.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0023 is in the 63rd percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

debianpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-553.5.1.el8_10
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2023-52607Moderate

kernel: powerpc/mm: Fix null-pointer dereference in pgtable_cache_add

Mar 6, 2024

References

git.kernel.org / stable/c/145febd85c3bcc5c74d87ef9a598fc7d9122d532
Patch
git.kernel.org / stable/c/21e45a7b08d7cd98d6a53c5fc5111879f2d96611
Patch
git.kernel.org / stable/c/aa28eecb43cac6e20ef14dfc50b8892c1fbcda5b
Patch
git.kernel.org / stable/c/ac3ed969a40357b0542d20f096a6d43acdfa6cc7
Patch
git.kernel.org / stable/c/d482d61025e303a2bef3733a011b6b740215cfa1
Patch
git.kernel.org / stable/c/f46c8a75263f97bda13c739ba1c90aced0d3b071
Patch
git.kernel.org / stable/c/f6781add1c311c17eff43e14c786004bbacf901e
Patch
git.kernel.org / stable/c/ffd29dc45bc0355393859049f6becddc3ed08f74
Patch
lists.debian.org / debian-lts-announce/2024/06/msg00017.html
Patch