-

CVE-2023-53541

In the Linux kernel, the following vulnerability has been resolved:

mtd: rawnand: brcmnand: Fix potential out-of-bounds access in oob write

When the oob buffer length is not in multiple of words, the oob write
function does out-of-bounds read on the oob source buffer at the last
iteration. Fix that by always checking length limit on the oob buffer
read and fill with 0xff when reaching the end of the buffer to the oob
registers.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version < 2bc3d6ac704ea7263175ea3da663fdbbb7f3dd8b
Version 27c5b17cd1b10564fa36f8f51e4b4b41436ecc32
Status affected
Version < 14b1d00520b4d6a4818364334ce472b79cfc8976
Version 27c5b17cd1b10564fa36f8f51e4b4b41436ecc32
Status affected
Version < aae45746f4aee9818296e0500e0703e9d8caa5b8
Version 27c5b17cd1b10564fa36f8f51e4b4b41436ecc32
Status affected
Version < d00b031266514a9395124704630b056a5185ec17
Version 27c5b17cd1b10564fa36f8f51e4b4b41436ecc32
Status affected
Version < 2353b7bb61e45e7cfd21505d0c6747ac8c9496a1
Version 27c5b17cd1b10564fa36f8f51e4b4b41436ecc32
Status affected
Version < 45fe4ad7f439799ee1b7b5f80bf82e8b34a98d25
Version 27c5b17cd1b10564fa36f8f51e4b4b41436ecc32
Status affected
Version < 648d1150a688698e37f7aaf302860180901cb30e
Version 27c5b17cd1b10564fa36f8f51e4b4b41436ecc32
Status affected
Version < 5d53244186c9ac58cb88d76a0958ca55b83a15cd
Version 27c5b17cd1b10564fa36f8f51e4b4b41436ecc32
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 4.2
Status affected
Version < 4.2
Version 0
Status unaffected
Version <= 4.14.*
Version 4.14.326
Status unaffected
Version <= 4.19.*
Version 4.19.295
Status unaffected
Version <= 5.4.*
Version 5.4.257
Status unaffected
Version <= 5.10.*
Version 5.10.195
Status unaffected
Version <= 5.15.*
Version 5.15.132
Status unaffected
Version <= 6.1.*
Version 6.1.54
Status unaffected
Version <= 6.5.*
Version 6.5.4
Status unaffected
Version <= *
Version 6.6
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.053
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String