PT-2023-7314 · Linux+2 · Linux Kernel+2
Mauro Matteo Cascella
·
Published
2023-11-21
·
Updated
2026-04-20
·
CVE-2023-6238
CVSS v2.0
6.8
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. This issue is related to the
nvme add user metadata() function and allows a privileged user to specify a small meta buffer, enabling the device to perform larger Direct Memory Access (DMA) into the same buffer. This can overwrite unrelated kernel memory, causing random kernel crashes and memory corruption. The exploitation of this vulnerability may impact the confidentiality, integrity, and availability of protected information.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Overflow
Memory Corruption
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Linux Kernel
Suse