PT-2025-38038 · Linux+2 · Linux Kernel+2

Published

2023-02-21

·

Updated

2026-05-26

·

CVE-2023-53320

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The mpi3mr get all tgt info() function contains several issues. The function incorrectly calculates the valid entry length in alltgt info by assuming an incorrect size for the header of the mpi3mr device map info struct. It also incorrectly calculates the valid entry length by excluding one entry and uses memcpy() when substitution would be sufficient. Additionally, it specifies an incorrect length to sg copy from buffer(), leading to a potential out-of-bounds write.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2026-03754
CVE-2023-53320
RHSA-2023:6583
RHSA-2023:7077
SUSE-SU-2025:03615-1
SUSE-SU-2025:3761-1

Affected Products

Astra Linux
Linux Kernel
Suse