PT-2025-37870 · Linux+2 · Linux Kernel+2
Published
2023-02-02
·
Updated
2025-10-31
·
CVE-2023-53265
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.0.0-1868 #1
Description
The Linux kernel contains a flaw within the UBI (Unsorted Block Images) subsystem related to VID (Volume ID) header handling. Specifically, the code does not adequately ensure that the sum of the VID header offset and VID header size remains within the allocated memory region, leading to a potential slab out-of-bounds write condition. This can result in a kernel crash.
Recommendations
versions prior to 6.0.0-1868 #1: Update the Linux kernel to a version that addresses this issue.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse