Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-52858

17
FAUCET Score

CVE-2023-52858 is a NULL pointer dereference vulnerability in the Linux kernel's MediaTek clock driver, specifically affecting the mtk_alloc_clk_data function. This medium-severity vulnerability (CVSS 6.2) can lead to a denial of service (A:H) if exploited locally (AV:L, AC:L), without requiring user interaction or privileges. There is currently no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.0, < 5.4.261CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.201CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.139CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.63CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.5.12CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.2MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.5
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.25%
Probability of exploitation in next 30 days
EPSS Percentile
16.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0025 is in the 25th percentile among its peer group of 3,052 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2023-52858Low

kernel: clk: mediatek: clk-mt7629: Add check for mtk_alloc_clk_data

May 21, 2024

References

git.kernel.org / stable/c/1d89430fc3158f872d492f1b88d07262f48290c0
Patch
git.kernel.org / stable/c/2befa515c1bb6cdd33c262b909d93d1973a219aa
Patch
git.kernel.org / stable/c/4f861b63945e076f9f003a5fad958174096df1ee
Patch
git.kernel.org / stable/c/5fbea47eebff5daeca7d918c99289bcd3ae4dc8d
Patch
git.kernel.org / stable/c/a836efc21ef04608333d6d05753e558ebd1f85d0
Patch
git.kernel.org / stable/c/e8ae4b49dd9cfde69d8de8c0c0cd7cf1b004482e
Patch
git.kernel.org / stable/c/e964d21dc034b650d719c4ea39564bec72b42f94
Patch