cbcvebase.
CVE-2023-52669
published 2024-05-17

CVE-2023-52669: In the Linux kernel, the following vulnerability has been resolved: crypto: s390/aes - Fix buffer overread in CTR mode When processing the last block, the s390…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
16.4th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: s390/aes - Fix buffer overread in CTR mode When processing the last block, the s390 ctr code will always read a whole block, even if there isn't a whole block of data left. Fix this by using the actual length left and copy it into a buffer first for processing.

Affected

18 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux
linuxlinux>= 0200f3ecc19660bebeabbcbaf212957fcf1dbf8f < cd51e26a3b89706beec64f2d8296cfb1c34e0c79cd51e26a3b89706beec64f2d8296cfb1c34e0c79
linuxlinux>= 0200f3ecc19660bebeabbcbaf212957fcf1dbf8f < a7f580cdb42ec3d53bbb7c4e4335a98423703285a7f580cdb42ec3d53bbb7c4e4335a98423703285
linuxlinux>= 0200f3ecc19660bebeabbcbaf212957fcf1dbf8f < dbc9a791a70ea47be9f2acf251700fe254a2ab23dbc9a791a70ea47be9f2acf251700fe254a2ab23
linuxlinux>= 0200f3ecc19660bebeabbcbaf212957fcf1dbf8f < d68ac38895e84446848b7647ab9458d54cacba3ed68ac38895e84446848b7647ab9458d54cacba3e
linuxlinux>= 0200f3ecc19660bebeabbcbaf212957fcf1dbf8f < e78f1a43e72daf77705ad5b9946de66fc708b874e78f1a43e72daf77705ad5b9946de66fc708b874
linuxlinux>= 0200f3ecc19660bebeabbcbaf212957fcf1dbf8f < d07f951903fa9922c375b8ab1ce81b18a0034e3bd07f951903fa9922c375b8ab1ce81b18a0034e3b
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 3.0 < 5.10.2105.10.210
linuxlinux_kernel>= 5.11 < 5.15.1495.15.149
linuxlinux_kernel>= 5.16 < 6.1.766.1.76
linuxlinux_kernel>= 6.2 < 6.6.156.6.15
linuxlinux_kernel>= 6.7 < 6.7.36.7.3

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.