cbcvebase.
CVE-2023-52511
published 2024-03-02

CVE-2023-52511: In the Linux kernel, the following vulnerability has been resolved: spi: sun6i: reduce DMA RX transfer width to single byte Through empirical testing it has…

PriorityP424medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.80%
53.2th percentile
In the Linux kernel, the following vulnerability has been resolved: spi: sun6i: reduce DMA RX transfer width to single byte Through empirical testing it has been determined that sometimes RX SPI transfers with DMA enabled return corrupted data. This is down to single or even multiple bytes lost during DMA transfer from SPI peripheral to memory. It seems the RX FIFO within the SPI peripheral can become confused when performing bus read accesses wider than a single byte to it during an active SPI transfer. This patch reduces the width of individual DMA read accesses to the RX FIFO to a single byte to mitigate that issue.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux>= 345980a3a5e5e1c99fc621e2ce878fb150ad2287 < ff05ed4ae214011464a0156f05cac1b0b46b5fbcff05ed4ae214011464a0156f05cac1b0b46b5fbc
linuxlinux>= 345980a3a5e5e1c99fc621e2ce878fb150ad2287 < e15bb292b24630ee832bfc7fd616bd72c7682bbbe15bb292b24630ee832bfc7fd616bd72c7682bbb
linuxlinux>= 345980a3a5e5e1c99fc621e2ce878fb150ad2287 < b3c21c9c7289692f4019f163c3b06d8bdf78b355b3c21c9c7289692f4019f163c3b06d8bdf78b355
linuxlinux>= 345980a3a5e5e1c99fc621e2ce878fb150ad2287 < 171f8a49f212e87a8b04087568e1b3d132e36a18171f8a49f212e87a8b04087568e1b3d132e36a18
linuxlinux_kernel< 5.15.1345.15.134
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1
linuxlinux_kernel>= 0 < 6.5.6-16.5.6-1
linuxlinux_kernel>= 0 < 6.5.6-16.5.6-1
linuxlinux_kernel>= 5.16 < 6.1.566.1.56
linuxlinux_kernel>= 6.2 < 6.5.66.5.6

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.