PT-2025-18821 · Linux+4 · Linux Kernel+4

Publicado

2023-03-20

·

Atualizado

2026-01-28

·

CVE-2023-53057

CVSS v3.1

7.1

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.2.0
Description A global-out-of-bounds issue has been identified in the Linux kernel's Bluetooth HCI component. The hci init stage sync function fails to properly validate the stage array, leading to potential out-of-bounds access. This issue is related to the amp init1 and amp init2 arrays, which lack an intentionally invalid element to prevent excessive access. The problem is resolved by adding an invalid element to the end of these arrays. The issue affects the /v6.2-bzimage/net/bluetooth/hci sync.c file, specifically the hci dev open sync function.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for this problem. As a temporary workaround, consider restricting access to the Bluetooth HCI component until a patch is available.

Exploit

Correção

DoS

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2025_16880
BDU:2025-06840
CVE-2023-53057
RHSA-2024:2394
RHSA-2024_2394
SUSE-SU-2025:01966-1
SUSE-SU-2025:02173-1
SUSE-SU-2025:2173-1
SUSE-SU-2025_02173-1

Produtos afetados

Astra Linux
Linux Kernel
Red Hat
Red Os
Suse