PT-2025-13326 · Linux+2 · Linux Kernel+2

Published

2023-01-31

·

Updated

2025-05-28

·

CVE-2023-52980

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A bug was found in the ublk driver of the Linux kernel. The issue occurs when assigning a large queue depth to a multiqueue ublk device, causing the ublk target to enter an incorrect state. The problem is due to an overflow bug in the ublk driver. Specifically, when the queue depth is set larger than 2728, the queue size overflows, leading to out-of-bounds memory access. The queue size in ublk device has been extended to unsigned int to fix the issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2025-06241
CVE-2023-52980

Affected Products

Astra Linux
Linux Kernel
Red Os