A NULL-pointer dereference in the Linux kernel Digital Phase Locked Loop (DPLL) subsystem, tracked as CVE-2023-6679, allows a local authenticated attacker to crash or restart an affected system. The flaw occurs in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.c when a DPLL pin-set netlink operation omits the optional DPLL_A_PIN_STATE attribute, which the vulnerable code reads unconditionally. Red Hat rated the issue CVSS 5.5 (Medium), citing low attack complexity, low privileges required, and high availability impact.
A kernel patch submitted by Jiri Pirko adds a presence check for DPLL_A_PIN_STATE before its value is used and credits Xingyuan Mo for reporting the issue. Red Hat released fixes for Red Hat Enterprise Linux 9 and RHEL 9.2 Extended Update Support; RHEL 9 kernel-rt remained affected in the vendor record, while listed RHEL 6, 7, and 8 variants were unaffected. No vendor-approved mitigation was available beyond applying the relevant kernel updates.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued kernel fixes for CVE-2023-6679 in RHEL 9, RHEL 9.2 Extended Update Support, and RHEL 9.2 EUS kernel-rt through RHSA-2024:0461, RHSA-2024:0448, and RHSA-2024:0439. The flaw is a local denial-of-service vulnerability caused by a NULL pointer dereference in the Linux kernel DPLL subsystem.
Jiri Pirko submitted a patch to prevent a NULL pointer dereference in dpll_pin_parent_pin_set() when a DPLL pin-set message omits the optional DPLL_A_PIN_STATE attribute. The issue was reported by Xingyuan Mo.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.