Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-52815

17
FAUCET Score

CVE-2023-52815 is a null pointer dereference vulnerability in the Linux kernel's AMDGPU virtual kernel mode setting (VKMS) driver, specifically within the amdgpu_vkms_conn_get_modes() function. This flaw, affecting Linux kernel versions, could lead to a system crash (denial of service) if the drm_cvt_mode() function fails to return a valid mode. Rated Medium with a CVSS score of 5.5, it requires local access and low privileges to exploit, with no user interaction needed. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, indicating a low immediate threat.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.15.140CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.64CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.5.13CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.6, < 6.6.3CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
14.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 64th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2023-52815Low

kernel: drm/amdgpu/vkms: fix a possible null pointer dereference

May 21, 2024

References

git.kernel.org / stable/c/33fb1a555354bd593f785935ddcb5d9dd4d3847f
Patch
git.kernel.org / stable/c/70f831f21155c692bb336c434936fd6f24f3f81a
Patch
git.kernel.org / stable/c/8c6c85a073768df68c1a3fea143d013a38c66d34
Patch
git.kernel.org / stable/c/cd90511557fdfb394bb4ac4c3b539b007383914c
Patch
git.kernel.org / stable/c/eaa03ea366c85ae3cb69c8d4bbc67c8bc2167a27
Patch