CVE-2023-52857Integer Overflow or Wraparound in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 96.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 21
Latest updateMay 22

Description

In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Fix coverity issue with unintentional integer overflow 1. Instead of multiplying 2 variable of different types. Change to assign a value of one variable and then multiply the other variable. 2. Add a int variable for multiplier calculation instead of calculating different types multiplier with dma_addr_t variable directly.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

NVDlinux/linux_kernel5.13.126.5.12+1
Debianlinux/linux_kernel< 6.1.133-1+2
CVEListV5linux/linux1a64a7aff8da352c9419de3d5c34343682916411a12bd675100531f9fb4508fd4430dd1632325a0e+5
debiandebian/linux< linux 6.1.133-1 (bookworm)
debiandebian/linux-6.1< linux 6.1.133-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2023-52857: In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Fix coverity issue with unintentional integer overflow 12024-05-21
GHSA
GHSA-mwgq-3h9h-3q6g: In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Fix coverity issue with unintentional integer overflow 12024-05-21

📋Vendor Advisories

2
Red Hat
kernel: drm/mediatek: Fix coverity issue with unintentional integer overflow2024-05-21
Debian
CVE-2023-52857: linux - In the Linux kernel, the following vulnerability has been resolved: drm/mediate...2023

💬Community

1
Bugzilla
CVE-2023-52857 kernel: drm/mediatek: Fix coverity issue with unintentional integer overflow2024-05-22