Bug 2400795 (CVE-2023-53513)
| Summary: | CVE-2023-53513 kernel: nbd: fix incomplete validation of ioctl arg | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw has been found in the Linux kernel’s NBD drivers.The issue stems from incomplete validation of IOCTL arguments passed to the NBD driver. Specifically, oversized or unchecked arguments may lead to a signed integer overflow in __block_write_full_page() and misuse of argument values cast to int in nbd_add_socket().
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2025-10-01 12:07:50 UTC
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2025100130-CVE-2023-53513-4667@gregkh/T This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:22095 https://access.redhat.com/errata/RHSA-2025:22095 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:22124 https://access.redhat.com/errata/RHSA-2025:22124 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:22387 https://access.redhat.com/errata/RHSA-2025:22387 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:22388 https://access.redhat.com/errata/RHSA-2025:22388 |