PT-2025-43104 · Linux+2 · Linux Kernel+2

Published

2023-07-10

·

Updated

2025-11-28

·

CVE-2023-53703

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains an issue within the AMD System Firmware Handler (SFH) HID driver. A shift operation involving the exp and shift variables can exceed the maximum allowable shift value for a u32 type, leading to a UBSAN (Undefined Behavior Sanitizer) shift-out-of-bounds error. This occurs in the amd sfh desc.c file at line 149. The issue is triggered during the processing of input reports, specifically within the get input rep() function and the amd sfh work buffer() workqueue. The error manifests as a shift exponent exceeding the maximum permissible value for a 64-bit unsigned integer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03790
CVE-2023-53703
SUSE-SU-2025:21040-1
SUSE-SU-2025:21052-1
SUSE-SU-2025:21056-1
SUSE-SU-2025:21064-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4128-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4140-1
SUSE-SU-2025:4141-1
SUSE-SU-2025:4301-1

Affected Products

Amd System Firmware Handler (Sfh) Hid Driver
Linux Kernel
Suse