VYPR
High severity7.8NVD Advisory· Published Mar 27, 2025· Updated Jun 17, 2026

CVE-2023-52980

CVE-2023-52980

Description

In the Linux kernel, the following vulnerability has been resolved:

block: ublk: extending queue_size to fix overflow

When validating drafted SPDK ublk target, in a case that assigning large queue depth to multiqueue ublk device, ublk target would run into a weird incorrect state. During rounds of review and debug, An overflow bug was found in ublk driver.

In ublk_cmd.h, UBLK_MAX_QUEUE_DEPTH is 4096 which means each ublk queue depth can be set as large as 4096. But when setting qd for a ublk device, sizeof(struct ublk_queue) + depth * sizeof(struct ublk_io) will be larger than 65535 if qd is larger than 2728. Then queue_size is overflowed, and ublk_get_queue() references a wrong pointer position. The wrong content of ublk_queue elements will lead to out-of-bounds memory access.

Extend queue_size in ublk_device as "unsigned int".

Affected products

11
  • osv-coords
    Range: >= 6.0.0, < 6.1.11
  • Linux/ublkllm-fuzzy
  • Linux/Kernelllm-fuzzy9 versions
    (expand)+ 8 more
    • (no CPE)
    • (no CPE)range: 6.0
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=6.0,<6.1.11
    • cpe:2.3:o:linux:linux_kernel:6.2:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.2:rc2:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.2:rc3:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.2:rc4:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.2:rc5:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.2:rc6:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.