CVE-2023-53495
EUVD-2025-3278001.10.2025, 12:15
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mvpp2_main: fix possible OOB write in mvpp2_ethtool_get_rxnfc() rules is allocated in ethtool_get_rxnfc and the size is determined by rule_cnt from user space. So rule_cnt needs to be check before using rules to avoid OOB writing or NULL pointer dereference.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| linux | linux_kernel | 5.2 ≤ 𝑥 < 5.4.257 |
| linux | linux_kernel | 5.5 ≤ 𝑥 < 5.10.195 |
| linux | linux_kernel | 5.11 ≤ 𝑥 < 5.15.132 |
| linux | linux_kernel | 5.16 ≤ 𝑥 < 6.1.54 |
| linux | linux_kernel | 6.2 ≤ 𝑥 < 6.5.4 |
| linux | linux_kernel | 6.6:rc1 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration
References