PT-2023-7314 · Linux+2 · Linux Kernel+2

Mauro Matteo Cascella

·

Publicado

2023-11-21

·

Atualizado

2026-04-20

·

CVE-2023-6238

CVSS v2.0

6.8

Média

VetorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. This issue is related to the nvme add user metadata() function and allows a privileged user to specify a small meta buffer, enabling the device to perform larger Direct Memory Access (DMA) into the same buffer. This can overwrite unrelated kernel memory, causing random kernel crashes and memory corruption. The exploitation of this vulnerability may impact the confidentiality, integrity, and availability of protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Memory Corruption

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08343
CVE-2023-6238
SUSE-SU-2024:2135-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1

Produtos afetados

Debian
Linux Kernel
Suse