PT-2025-37870 · Linux+2 · Linux Kernel+2

Published

2023-02-02

·

Updated

2025-10-31

·

CVE-2023-53265

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.0.0-1868 #1
Description The Linux kernel contains a flaw within the UBI (Unsorted Block Images) subsystem related to VID (Volume ID) header handling. Specifically, the code does not adequately ensure that the sum of the VID header offset and VID header size remains within the allocated memory region, leading to a potential slab out-of-bounds write condition. This can result in a kernel crash.
Recommendations versions prior to 6.0.0-1868 #1: Update the Linux kernel to a version that addresses this issue.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2026-02443
CVE-2023-53265
OESA-2025-2553
SUSE-SU-2025:03613-1
SUSE-SU-2025:03614-1
SUSE-SU-2025:03615-1
SUSE-SU-2025:03626-1
SUSE-SU-2025:03628-1
SUSE-SU-2025:3716-1
SUSE-SU-2025:3761-1

Affected Products

Astra Linux
Linux Kernel
Suse