CVE-2023-53019
published 2025-03-27CVE-2023-53019: In the Linux kernel, the following vulnerability has been resolved: net: mdio: validate parameter addr in mdiobus_get_phy() The caller may pass any value as…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.19%
8.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: mdio: validate parameter addr in mdiobus_get_phy()
The caller may pass any value as addr, what may result in an out-of-bounds
access to array mdio_map. One existing case is stmmac_init_phy() that
may pass -1 as addr. Therefore validate addr before using it.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.11-1 (bookworm) | linux 6.1.11-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 7f854420fbfe9d49afe2ffb1df052cfe8e215541 < 1d80c259dfbadefa61b7ea334dfce5cb57f8c72f | 1d80c259dfbadefa61b7ea334dfce5cb57f8c72f |
| linux | linux | >= 7f854420fbfe9d49afe2ffb1df052cfe8e215541 < c431a3d642593bbdb99e8a9e3eed608b730db6f8 | c431a3d642593bbdb99e8a9e3eed608b730db6f8 |
| linux | linux | >= 7f854420fbfe9d49afe2ffb1df052cfe8e215541 < 8a7b9560a3a8eb8724888c426e05926752f73aa0 | 8a7b9560a3a8eb8724888c426e05926752f73aa0 |
| linux | linux | >= 7f854420fbfe9d49afe2ffb1df052cfe8e215541 < 4bc5f1f6bc94e695dfd912122af96e7115a0ddb8 | 4bc5f1f6bc94e695dfd912122af96e7115a0ddb8 |
| linux | linux | >= 7f854420fbfe9d49afe2ffb1df052cfe8e215541 < ad67de330d83e8078372b52af18ffe8d39e26c85 | ad67de330d83e8078372b52af18ffe8d39e26c85 |
| linux | linux | >= 7f854420fbfe9d49afe2ffb1df052cfe8e215541 < 7879626296e6ffd838ae0f2af1ab49ee46354973 | 7879626296e6ffd838ae0f2af1ab49ee46354973 |
| linux | linux | >= 7f854420fbfe9d49afe2ffb1df052cfe8e215541 < 867dbe784c5010a466f00a7d1467c1c5ea569c75 | 867dbe784c5010a466f00a7d1467c1c5ea569c75 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.11-1 | 6.1.11-1 |
| linux | linux_kernel | >= 0 < 6.1.11-1 | 6.1.11-1 |
| linux | linux_kernel | >= 0 < 6.1.11-1 | 6.1.11-1 |
| linux | linux_kernel | >= 4.15 < 4.19.272 | 4.19.272 |
| linux | linux_kernel | >= 4.20 < 5.4.231 | 5.4.231 |
| linux | linux_kernel | >= 4.5 < 4.14.305 | 4.14.305 |
| linux | linux_kernel | >= 5.11 < 5.15.91 | 5.15.91 |
| linux | linux_kernel | >= 5.16 < 6.1.9 | 6.1.9 |
| linux | linux_kernel | >= 5.5 < 5.10.166 | 5.10.166 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4x8g-3q83-5465: In the Linux kernel, the following vulnerability has been resolved:
net: mdio: validate parameter addr in mdiobus_get_phy()
The caller may pass any
ghsa_unreviewed·2025-03-27
CVE-2023-53019 [HIGH] CWE-129 GHSA-4x8g-3q83-5465: In the Linux kernel, the following vulnerability has been resolved:
net: mdio: validate parameter addr in mdiobus_get_phy()
The caller may pass any
In the Linux kernel, the following vulnerability has been resolved:
net: mdio: validate parameter addr in mdiobus_get_phy()
The caller may pass any value as addr, what may result in an out-of-bounds
access to array mdio_map. One existing case is stmmac_init_phy() that
may pass -1 as addr. Therefore validate addr before using it.
OSV
CVE-2023-53019: In the Linux kernel, the following vulnerability has been resolved: net: mdio: validate parameter addr in mdiobus_get_phy() The caller may pass any va
osv·2025-03-27·CVSS 7.8
CVE-2023-53019 [HIGH] CVE-2023-53019: In the Linux kernel, the following vulnerability has been resolved: net: mdio: validate parameter addr in mdiobus_get_phy() The caller may pass any va
In the Linux kernel, the following vulnerability has been resolved: net: mdio: validate parameter addr in mdiobus_get_phy() The caller may pass any value as addr, what may result in an out-of-bounds access to array mdio_map. One existing case is stmmac_init_phy() that may pass -1 as addr. Therefore validate addr before using it.
Red Hat
kernel: net: mdio: validate parameter addr in mdiobus_get_phy()
vendor_redhat·2025-03-27·CVSS 7.8
CVE-2023-53019 [HIGH] CWE-125 kernel: net: mdio: validate parameter addr in mdiobus_get_phy()
kernel: net: mdio: validate parameter addr in mdiobus_get_phy()
In the Linux kernel, the following vulnerability has been resolved:
net: mdio: validate parameter addr in mdiobus_get_phy()
The caller may pass any value as addr, what may result in an out-of-bounds
access to array mdio_map. One existing case is stmmac_init_phy() that
may pass -1 as addr. Therefore validate addr before using it.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 8) - Fix deferred
Package: kernel-rt (Red Hat Enterprise Linux 8) - Fix deferred
Packag
Debian
CVE-2023-53019: linux - In the Linux kernel, the following vulnerability has been resolved: net: mdio: ...
vendor_debian·2023·CVSS 7.8
CVE-2023-53019 [HIGH] CVE-2023-53019: linux - In the Linux kernel, the following vulnerability has been resolved: net: mdio: ...
In the Linux kernel, the following vulnerability has been resolved: net: mdio: validate parameter addr in mdiobus_get_phy() The caller may pass any value as addr, what may result in an out-of-bounds access to array mdio_map. One existing case is stmmac_init_phy() that may pass -1 as addr. Therefore validate addr before using it.
Scope: local
bookworm: resolved (fixed in 6.1.11-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.11-1)
sid: resolved (fixed in 6.1.11-1)
trixie: resolved (fixed in 6.1.11-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1d80c259dfbadefa61b7ea334dfce5cb57f8c72fhttps://git.kernel.org/stable/c/4bc5f1f6bc94e695dfd912122af96e7115a0ddb8https://git.kernel.org/stable/c/7879626296e6ffd838ae0f2af1ab49ee46354973https://git.kernel.org/stable/c/867dbe784c5010a466f00a7d1467c1c5ea569c75https://git.kernel.org/stable/c/8a7b9560a3a8eb8724888c426e05926752f73aa0https://git.kernel.org/stable/c/ad67de330d83e8078372b52af18ffe8d39e26c85https://git.kernel.org/stable/c/c431a3d642593bbdb99e8a9e3eed608b730db6f8
2025-03-27
Published