#VU106184 Out-of-bounds read in Linux kernel - CVE-2023-53019


Vulnerability identifier: #VU106184

Vulnerability risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2023-53019

CWE-ID: CWE-125

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds read error within the EXPORT_SYMBOL() function in drivers/net/phy/mdio_bus.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions


External links
https://git.kernel.org/stable/c/1d80c259dfbadefa61b7ea334dfce5cb57f8c72f
https://git.kernel.org/stable/c/4bc5f1f6bc94e695dfd912122af96e7115a0ddb8
https://git.kernel.org/stable/c/7879626296e6ffd838ae0f2af1ab49ee46354973
https://git.kernel.org/stable/c/867dbe784c5010a466f00a7d1467c1c5ea569c75
https://git.kernel.org/stable/c/8a7b9560a3a8eb8724888c426e05926752f73aa0
https://git.kernel.org/stable/c/ad67de330d83e8078372b52af18ffe8d39e26c85
https://git.kernel.org/stable/c/c431a3d642593bbdb99e8a9e3eed608b730db6f8


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability