cbcvebase.
CVE-2023-52606
published 2024-03-06

CVE-2023-52606: In the Linux kernel, the following vulnerability has been resolved: powerpc/lib: Validate size for vector operations Some of the fp/vmx code in sstep.c assume…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.5th percentile
In the Linux kernel, the following vulnerability has been resolved: powerpc/lib: Validate size for vector operations Some of the fp/vmx code in sstep.c assume a certain maximum size for the instructions being emulated. The size of those operations however is determined separately in analyse_instr(). Add a check to validate the assumption on the maximum size of the operations, so as to prevent any unintended kernel stack corruption.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux>= c22435a5f3d8f85ea162ae523a6ba60a58521ba5 < 42084a428a139f1a429f597d44621e3a18f3e41442084a428a139f1a429f597d44621e3a18f3e414
linuxlinux>= c22435a5f3d8f85ea162ae523a6ba60a58521ba5 < 0580f4403ad33f379eef865c2a6fe94de37febdf0580f4403ad33f379eef865c2a6fe94de37febdf
linuxlinux>= c22435a5f3d8f85ea162ae523a6ba60a58521ba5 < beee482cc4c9a6b1dcffb2e190b4fd8782258678beee482cc4c9a6b1dcffb2e190b4fd8782258678
linuxlinux>= c22435a5f3d8f85ea162ae523a6ba60a58521ba5 < de4f5ed63b8a199704d8cdcbf810309d7eb4b36bde4f5ed63b8a199704d8cdcbf810309d7eb4b36b
linuxlinux>= c22435a5f3d8f85ea162ae523a6ba60a58521ba5 < abd26515d4b767ba48241eea77b28ce0872aef3eabd26515d4b767ba48241eea77b28ce0872aef3e
linuxlinux>= c22435a5f3d8f85ea162ae523a6ba60a58521ba5 < 28b8ba8eebf26f66d9f2df4ba550b6b3b136082c28b8ba8eebf26f66d9f2df4ba550b6b3b136082c
linuxlinux>= c22435a5f3d8f85ea162ae523a6ba60a58521ba5 < 848e1d7fd710900397e1d0e7584680c1c04e3afd848e1d7fd710900397e1d0e7584680c1c04e3afd
linuxlinux>= c22435a5f3d8f85ea162ae523a6ba60a58521ba5 < 8f9abaa6d7de0a70fc68acaedce290c1f96e2e598f9abaa6d7de0a70fc68acaedce290c1f96e2e59
linuxlinux_kernel< 4.19.3074.19.307
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 5.4.0-181.2015.4.0-181.201
linuxlinux_kernel>= 0 < 5.15.0-106.1165.15.0-106.116
linuxlinux_kernel>= 4.20 < 5.4.2695.4.269
linuxlinux_kernel>= 5.11 < 5.15.1495.15.149
linuxlinux_kernel>= 5.16 < 6.1.776.1.77
linuxlinux_kernel>= 5.5 < 5.10.2105.10.210
linuxlinux_kernel>= 6.2 < 6.6.166.6.16
linuxlinux_kernel>= 6.7 < 6.7.46.7.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.