CVE-2023-52507: Linux Kernel

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: nfc: nci: assert requested protocol is valid The protocol is used in a bit mask to determine if the protocol is supported. Assert the provided protocol is less than the maximum defined so it doesn't potentially perform a shift-out-of-bounds and provide a clearer error for undefined protocols vs unsupported ones.

Affected products

  • Linux Linux Kernel: from 3.2, before 4.14.328 (fixed in 4.14.328); from 4.15, before 4.19.297 (fixed in 4.19.297); from 4.20, before 5.4.259 (fixed in 5.4.259); from 5.5, before 5.10.199 (fixed in 5.10.199); from 5.11, before 5.15.136 (fixed in 5.15.136); from 5.16, before 6.1.59 (fixed in 6.1.59); …

Published 2024-03-02. Last modified 2026-06-17.