cbcvebase.
CVE-2023-53019
published 2025-03-27

CVE-2023-53019: In the Linux kernel, the following vulnerability has been resolved: net: mdio: validate parameter addr in mdiobus_get_phy() The caller may pass any value as…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.19%
8.8th percentile
In the Linux kernel, the following vulnerability has been resolved: net: mdio: validate parameter addr in mdiobus_get_phy() The caller may pass any value as addr, what may result in an out-of-bounds access to array mdio_map. One existing case is stmmac_init_phy() that may pass -1 as addr. Therefore validate addr before using it.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.11-1 (bookworm)linux 6.1.11-1 (bookworm)
linuxlinux
linuxlinux>= 7f854420fbfe9d49afe2ffb1df052cfe8e215541 < 1d80c259dfbadefa61b7ea334dfce5cb57f8c72f1d80c259dfbadefa61b7ea334dfce5cb57f8c72f
linuxlinux>= 7f854420fbfe9d49afe2ffb1df052cfe8e215541 < c431a3d642593bbdb99e8a9e3eed608b730db6f8c431a3d642593bbdb99e8a9e3eed608b730db6f8
linuxlinux>= 7f854420fbfe9d49afe2ffb1df052cfe8e215541 < 8a7b9560a3a8eb8724888c426e05926752f73aa08a7b9560a3a8eb8724888c426e05926752f73aa0
linuxlinux>= 7f854420fbfe9d49afe2ffb1df052cfe8e215541 < 4bc5f1f6bc94e695dfd912122af96e7115a0ddb84bc5f1f6bc94e695dfd912122af96e7115a0ddb8
linuxlinux>= 7f854420fbfe9d49afe2ffb1df052cfe8e215541 < ad67de330d83e8078372b52af18ffe8d39e26c85ad67de330d83e8078372b52af18ffe8d39e26c85
linuxlinux>= 7f854420fbfe9d49afe2ffb1df052cfe8e215541 < 7879626296e6ffd838ae0f2af1ab49ee463549737879626296e6ffd838ae0f2af1ab49ee46354973
linuxlinux>= 7f854420fbfe9d49afe2ffb1df052cfe8e215541 < 867dbe784c5010a466f00a7d1467c1c5ea569c75867dbe784c5010a466f00a7d1467c1c5ea569c75
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 4.15 < 4.19.2724.19.272
linuxlinux_kernel>= 4.20 < 5.4.2315.4.231
linuxlinux_kernel>= 4.5 < 4.14.3054.14.305
linuxlinux_kernel>= 5.11 < 5.15.915.15.91
linuxlinux_kernel>= 5.16 < 6.1.96.1.9
linuxlinux_kernel>= 5.5 < 5.10.1665.10.166

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.