Unrated severityNVD Advisory· Published May 2, 2025· Updated May 4, 2025
xsk: Add missing overflow check in xdp_umem_reg
CVE-2023-53080
Description
In the Linux kernel, the following vulnerability has been resolved:
xsk: Add missing overflow check in xdp_umem_reg
The number of chunks can overflow u32. Make sure to return -EINVAL on overflow. Also remove a redundant u32 cast assigning umem->npgs.
Affected products
10- osv-coords8 versionspkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2012%20SP5pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSSpkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSSpkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSSpkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5pkg:rpm/suse/kgraft-patch-SLE12-SP5_Update_69&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2012%20SP5
< 4.12.14-122.261.1+ 7 more
- (no CPE)range: < 4.12.14-122.261.1
- (no CPE)range: < 4.12.14-122.261.1
- (no CPE)range: < 4.12.14-122.261.1
- (no CPE)range: < 4.12.14-122.261.1
- (no CPE)range: < 4.12.14-122.261.1
- (no CPE)range: < 4.12.14-122.261.1
- (no CPE)range: < 4.12.14-122.261.1
- (no CPE)range: < 1-8.3.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- git.kernel.org/stable/c/3cfc3564411acf96bf2fb791f706a1aa4f872c1dmitre
- git.kernel.org/stable/c/580634b03a55f04a3c1968bcbd97736c079c6601mitre
- git.kernel.org/stable/c/a069909acc4435eeb41d05ccc03baa447cc01b7emitre
- git.kernel.org/stable/c/bb2e3bfb2a79db0c2057c6f701b782954394c67fmitre
- git.kernel.org/stable/c/c7df4813b149362248d6ef7be41a311e27bf75femitre
News mentions
0No linked articles in our index yet.