PT-2025-13333 · Linux+2 · Linux Kernel+2
Published
2023-01-19
·
Updated
2025-05-28
·
CVE-2023-52987
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability has been resolved in the Linux kernel related to the ASoC: SOF: ipc4-mtrace component. The issue involves preventing an underflow in the
sof ipc4 priority mask dfs write() function. The id variable, which comes from the user, was changed to an unsigned type to prevent an array underflow.Recommendations
For the affected Linux kernel versions, consider updating to a version that includes the fix for the
sof ipc4 priority mask dfs write() function underflow issue. As a temporary workaround, consider restricting the input for the id variable to prevent potential underflow exploitation.Exploit
Fix
Integer Underflow
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Os