-

CVE-2023-54057

iommu/amd: Add a length limitation for the ivrs_acpihid command-line parameter

In the Linux kernel, the following vulnerability has been resolved:

iommu/amd: Add a length limitation for the ivrs_acpihid command-line parameter

The 'acpiid' buffer in the parse_ivrs_acpihid function may overflow,
because the string specifier in the format string sscanf()
has no width limitation.

Found by InfoTeCS on behalf of Linux Verification Center
(linuxtesting.org) with SVACE.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version ca3bf5d47cec8b7614bcb2e9132c40081d6d81db
Version < 5e97dc748d13fad582136ba0c8cec215c7aeeb17
Status affected
Version ca3bf5d47cec8b7614bcb2e9132c40081d6d81db
Version < f2a5ec7f7b28f9b9cd5fac232ff51019a7f7b9e9
Status affected
Version ca3bf5d47cec8b7614bcb2e9132c40081d6d81db
Version < c513043e0afe6a8ba79d00af358655afabb576d2
Status affected
Version ca3bf5d47cec8b7614bcb2e9132c40081d6d81db
Version < 2ae19ac3ea82a5b87a81c10adbb497c9e58bdd60
Status affected
Version ca3bf5d47cec8b7614bcb2e9132c40081d6d81db
Version < 63cd11165e5e0ea2012254c764003eda1f9adb7d
Status affected
Version ca3bf5d47cec8b7614bcb2e9132c40081d6d81db
Version < b6b26d86c61c441144c72f842f7469bb686e1211
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 4.7
Status affected
Version 0
Version < 4.7
Status unaffected
Version <= 5.4.*
Version 5.4.237
Status unaffected
Version <= 5.10.*
Version 5.10.175
Status unaffected
Version <= 5.15.*
Version 5.15.103
Status unaffected
Version <= 6.1.*
Version 6.1.16
Status unaffected
Version <= 6.2.*
Version 6.2.3
Status unaffected
Version <= *
Version 6.3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.144
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.