-

CVE-2023-54168

RDMA/mlx4: Prevent shift wrapping in set_user_sq_size()

In the Linux kernel, the following vulnerability has been resolved:

RDMA/mlx4: Prevent shift wrapping in set_user_sq_size()

The ucmd->log_sq_bb_count variable is controlled by the user so this
shift can wrap.  Fix it by using check_shl_overflow() in the same way
that it was done in commit 515f60004ed9 ("RDMA/hns: Prevent undefined
behavior in hns_roce_set_user_sq_size()").
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 839041329fd3410e07d614f81e75bb43367d8f89
Version < 3d5ae269c4bd392ec1edbfb3bd031b8f42d7feff
Status affected
Version 839041329fd3410e07d614f81e75bb43367d8f89
Version < 8feca625900777e02a449e53fe4121339934c38a
Status affected
Version 839041329fd3410e07d614f81e75bb43367d8f89
Version < 9ad3221c86cc9c6305594b742d4a72dfbd4ea579
Status affected
Version 839041329fd3410e07d614f81e75bb43367d8f89
Version < 9911be2155720221a4f1f722b22bd0e2388d8bcf
Status affected
Version 839041329fd3410e07d614f81e75bb43367d8f89
Version < 3ce0df3493277b9df275cb8455d9c677ae701230
Status affected
Version 839041329fd3410e07d614f81e75bb43367d8f89
Version < 196a6df08b08699ace4ce70e1efcdd9081b6565f
Status affected
Version 839041329fd3410e07d614f81e75bb43367d8f89
Version < a183905869e692b6b7805b7472235585eff8e429
Status affected
Version 839041329fd3410e07d614f81e75bb43367d8f89
Version < d50b3c73f1ac20dabc53dc6e9d64ce9c79a331eb
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 2.6.24
Status affected
Version 0
Version < 2.6.24
Status unaffected
Version <= 4.19.*
Version 4.19.283
Status unaffected
Version <= 5.4.*
Version 5.4.243
Status unaffected
Version <= 5.10.*
Version 5.10.180
Status unaffected
Version <= 5.15.*
Version 5.15.111
Status unaffected
Version <= 6.1.*
Version 6.1.28
Status unaffected
Version <= 6.2.*
Version 6.2.15
Status unaffected
Version <= 6.3.*
Version 6.3.2
Status unaffected
Version <= *
Version 6.4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.144
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.