PT-2025-18872 · Linux+5 · Linux Kernel+5

Published

2023-11-07

·

Updated

2026-02-02

·

CVE-2023-53108

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.3.0-20230221.rc0.git4.99b8246b2d71.300.fc37.s390x+debug
Description A vulnerability in the Linux kernel has been resolved, specifically in the net/iucv module. The issue is related to the size of interrupt data, where iucv irq data needs to be 4 bytes larger to accommodate data written by the z/VM hypervisor in case a CPU is deconfigured. This vulnerability can cause a kmalloc Redzone overwrite, as reported by the BUG dma-kmalloc-64. The estimated number of potentially affected devices worldwide is not available.
Recommendations For Linux kernel versions prior to 6.3.0-20230221.rc0.git4.99b8246b2d71.300.fc37.s390x+debug, update to a version that includes the fix for the net/iucv module, ensuring that iucv irq data is 4 bytes larger. As a temporary workaround, consider disabling the iucv cpu prepare() function until a patch is available. Restrict access to the vulnerable iucv irq data to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2025_16880
CESA-2023_7077
CVE-2023-53108
RHSA-2023:6583
RHSA-2023:7077
RHSA-2023_6583
RHSA-2023_7077
SUSE-SU-2025:01918-1
SUSE-SU-2025:01966-1
SUSE-SU-2025:01983-1
SUSE-SU-2025:02173-1
SUSE-SU-2025:02262-1
SUSE-SU-2025:2173-1
SUSE-SU-2025_01983-1
SUSE-SU-2025_02173-1
SUSE-SU-2025_02262-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Red Os
Suse