LiveActive security incident?Get immediate response
CVE Record

CVE-2023-52708: mmc: mmc_spi: fix error handling in mmc_spi_probe()

In the Linux kernel, the following vulnerability has been resolved: mmc: mmc_spi: fix error handling in mmc_spi_probe() If mmc_add_host() fails, it doesn't need to call mmc_remove_host(), or it will cause null-ptr-deref, because of deleting a not added device in mmc_remove_host(). To fix this, goto label 'fail_glue_init', if mmc_add_host() fails, and change the label 'fail_add_host' to 'fail_gpiod_request'.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2023-52708 is a Linux kernel bug in the MMC-over-SPI driver’s startup error handling. Under a specific failure path, the kernel may dereference a null pointer while cleaning up, likely causing a crash or denial of service. Public sources do not report active exploitation or a CVSS score.

Executive priority

Treat as a routine-to-prioritized kernel maintenance item. Prioritize systems where MMC-over-SPI is used or where kernel crashes affect availability. There is no public evidence of active exploitation in the provided sources.

Technical view

The issue is in mmc_spi_probe(). If mmc_add_host() fails, the code incorrectly calls mmc_remove_host() for a host that was not added, causing a null pointer dereference. Stable kernel commits adjust the failure labels so cleanup skips mmc_remove_host() in this path.

Likely exposure

Exposure appears limited to Linux systems using the mmc_spi driver, commonly relevant to embedded or hardware-integrated environments. The source bundle lists Linux kernel versions including 2.6.24, 5.4.232, 5.10.169, 5.15.95, 6.1.13, and 6.2 as affected, but version-range detail is incomplete.

Exploitation context

No CISA KEV listing or cited source indicates active exploitation. The bug requires the vulnerable driver path and an mmc_add_host() failure condition, so practical exposure is likely configuration- and hardware-dependent. The documented impact is kernel null pointer dereference, not code execution.

Researcher notes

The CVE record provides no CVSS, CWE, or exploit evidence. Analysis should focus on driver reachability, kernel branch mapping, and whether the fix commit is present. Avoid assuming broad internet exposure; this is a kernel driver error-path issue tied to specific hardware and configuration.

Mitigation direction

  • Check your kernel vendor’s advisory for fixed packages covering CVE-2023-52708.
  • Update to a kernel containing the referenced stable fix for your maintained branch.
  • Prioritize embedded or appliance systems using MMC-over-SPI hardware.
  • If mmc_spi is unused, review vendor-supported options to disable or avoid loading it.

Validation and detection

  • Inventory Linux kernel versions across embedded, appliance, and server fleets.
  • Check whether the mmc_spi driver is built, loaded, or required.
  • Compare installed kernels against vendor fixed-version guidance.
  • Confirm patched kernels include one of the referenced stable commits.
  • Monitor kernel logs for driver probe failures or null pointer crashes.
Prepared
Confidence
medium
Sources
7

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2023-52708 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
2ADP providers
6Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux15a0580ced081a0f7dc2deea8a4812bdc5e9a109, 15a0580ced081a0f7dc2deea8a4812bdc5e9a109, 15a0580ced081a0f7dc2deea8a4812bdc5e9a109, 15a0580ced081a0f7dc2deea8a4812bdc5e9a109, 15a0580ced081a0f7dc2deea8a4812bdc5e9a109unaffected
LinuxLinux2.6.24, 0, 5.4.232, 5.10.169, 5.15.95, 6.1.13, 6.2affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.