CVE-2023-52976: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: efi: fix potential NULL deref in efi_mem_reserve_persistent When iterating on a linked list, a result of memremap is dereferenced without checking it for NULL. This patch adds a check that falls back on allocating a new page in case memremap doesn't succeed. Found by Linux Verification Center (linuxtesting.org) with SVACE. [ardb: return -ENOMEM instead of breaking out of the loop]

Affected products

  • Linux Linux Kernel: from 5.1.16, before 5.4.232 (fixed in 5.4.232); from 5.5, before 5.10.168 (fixed in 5.10.168); from 5.11, before 5.15.93 (fixed in 5.15.93); from 5.16, before 6.1.11 (fixed in 6.1.11); version 6.2 only

Published 2025-03-27. Last modified 2026-06-17.