PT-2025-54068 · Linux+1 · Linux Kernel+1
Published
2023-04-04
·
Updated
2026-01-01
·
CVE-2023-54239
CVSS v2.0
3.5
Low
| Vector | AV:L/AC:H/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.3.0-rc2-eeac8ede1755+
Description
The Linux kernel contained a flaw within the iommufd subsystem related to an improper check for user pointer overflows. Syzkaller testing revealed that creating a map with a user virtual address (VA) that wraps past zero could trigger warnings and issues with page pinning due to invalid arguments. This could potentially lead to unexpected behavior or system instability. The issue stemmed from a lack of proper validation when creating pages with a user pointer and size that could result in a mathematical overflow. The vulnerable code is located in the
pfn reader user pin function.Recommendations
Update to a version newer than 6.3.0-rc2-eeac8ede1755+ to address this issue.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel
Red Hat