CVE-2023-52669 — Out-of-bounds Write in Linux
Severity
7.8HIGHNVD
OSV7.5
EPSS
0.0%
top 96.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 17
Latest updateJun 26
Description
In the Linux kernel, the following vulnerability has been resolved:
crypto: s390/aes - Fix buffer overread in CTR mode
When processing the last block, the s390 ctr code will always read
a whole block, even if there isn't a whole block of data left. Fix
this by using the actual length left and copy it into a buffer first
for processing.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages4 packages
▶CVEListV5linux/linux0200f3ecc19660bebeabbcbaf212957fcf1dbf8f — cd51e26a3b89706beec64f2d8296cfb1c34e0c79+6
Also affects: Debian Linux 10.0