cbcvebase.
CVE-2023-52612
published 2024-03-18

CVE-2023-52612: In the Linux kernel, the following vulnerability has been resolved: crypto: scomp - fix req->dst buffer overflow The req->dst buffer size should be checked…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
18.9th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: scomp - fix req->dst buffer overflow The req->dst buffer size should be checked before copying from the scomp_scratch->dst to avoid req->dst buffer overflow problem.

Affected

25 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux
linuxlinux>= 1ab53a77b772bf7369464a0e4fa6fd6499acf8f1 < 1142d65c5b881590962ad763f94505b6dd67d2fe1142d65c5b881590962ad763f94505b6dd67d2fe
linuxlinux>= 1ab53a77b772bf7369464a0e4fa6fd6499acf8f1 < e0e3f4a18784182cfe34e20c00eca11e78d53e76e0e3f4a18784182cfe34e20c00eca11e78d53e76
linuxlinux>= 1ab53a77b772bf7369464a0e4fa6fd6499acf8f1 < 4518dc468cdd796757190515a9be7408adc8911e4518dc468cdd796757190515a9be7408adc8911e
linuxlinux>= 1ab53a77b772bf7369464a0e4fa6fd6499acf8f1 < a5f2f91b3fd7387e5102060809316a0f8f0bc625a5f2f91b3fd7387e5102060809316a0f8f0bc625
linuxlinux>= 1ab53a77b772bf7369464a0e4fa6fd6499acf8f1 < 4df0c942d04a67df174195ad8082f6e30e7f71a54df0c942d04a67df174195ad8082f6e30e7f71a5
linuxlinux>= 1ab53a77b772bf7369464a0e4fa6fd6499acf8f1 < 7d9e5bed036a7f9e2062a137e97e3c1e77fb87597d9e5bed036a7f9e2062a137e97e3c1e77fb8759
linuxlinux>= 1ab53a77b772bf7369464a0e4fa6fd6499acf8f1 < 71c6670f9f032ec67d8f4e3f8db4646bf5a6288371c6670f9f032ec67d8f4e3f8db4646bf5a62883
linuxlinux>= 1ab53a77b772bf7369464a0e4fa6fd6499acf8f1 < 744e1885922a9943458954cfea917b31064b4131744e1885922a9943458954cfea917b31064b4131
linuxlinux_kernel>= 0 < 5.10.209-15.10.209-1
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 5.4.0-176.1965.4.0-176.196
linuxlinux_kernel>= 0 < 5.15.0-102.1125.15.0-102.112
linuxlinux_kernel>= 0 < 4.15.0-231.2434.15.0-231.243
linuxlinux_kernel>= 4.10 < 4.19.3064.19.306
linuxlinux_kernel>= 4.20 < 5.4.2685.4.268
linuxlinux_kernel>= 5.11 < 5.15.1485.15.148
linuxlinux_kernel>= 5.16 < 6.1.756.1.75
linuxlinux_kernel>= 5.5 < 5.10.2095.10.209
linuxlinux_kernel>= 6.2 < 6.6.146.6.14
linuxlinux_kernel>= 6.7 < 6.7.26.7.2

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.