cbcvebase.
CVE-2023-53034
published 2025-04-16

CVE-2023-53034: In the Linux kernel, the following vulnerability has been resolved: ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans There is a kernel…

PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.20%
10.5th percentile
In the Linux kernel, the following vulnerability has been resolved: ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans There is a kernel API ntb_mw_clear_trans() would pass 0 to both addr and size. This would make xlate_pos negative. [ 23.734156] switchtec switchtec0: MW 0: part 0 addr 0x0000000000000000 size 0x0000000000000000 [ 23.734158] ================================================================================ [ 23.734172] UBSAN: shift-out-of-bounds in drivers/ntb/hw/mscc/ntb_hw_switchtec.c:293:7 [ 23.734418] shift exponent -1 is negative Ensuring xlate_pos is a positive or zero before BIT.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= 1e2fd202f8593985cdadca32e0c322f98e7fe7cb < f56951f211f181410a383d305e8d370993e45294f56951f211f181410a383d305e8d370993e45294
linuxlinux>= 1e2fd202f8593985cdadca32e0c322f98e7fe7cb < 5b6857bb3bfb0dae17fab1e42c1e82c204a508b15b6857bb3bfb0dae17fab1e42c1e82c204a508b1
linuxlinux>= 1e2fd202f8593985cdadca32e0c322f98e7fe7cb < 2429bdf26a0f3950fdd996861e9c1a3873af1dbe2429bdf26a0f3950fdd996861e9c1a3873af1dbe
linuxlinux>= 1e2fd202f8593985cdadca32e0c322f98e7fe7cb < 7ed22f8d8be26225a78cf5e85b2036421a6bf2d57ed22f8d8be26225a78cf5e85b2036421a6bf2d5
linuxlinux>= 1e2fd202f8593985cdadca32e0c322f98e7fe7cb < c61a3f2df162ba424be0141649a9ef5f28eaccc1c61a3f2df162ba424be0141649a9ef5f28eaccc1
linuxlinux>= 1e2fd202f8593985cdadca32e0c322f98e7fe7cb < cb153bdc1812a3375639ed6ca5f147eaefb65349cb153bdc1812a3375639ed6ca5f147eaefb65349
linuxlinux>= 1e2fd202f8593985cdadca32e0c322f98e7fe7cb < 36d32cfb00d42e865396424bb5d340fc0a28870d36d32cfb00d42e865396424bb5d340fc0a28870d
linuxlinux>= 1e2fd202f8593985cdadca32e0c322f98e7fe7cb < 0df2e03e4620548b41891b4e0d1bd9d2e0d8a39a0df2e03e4620548b41891b4e0d1bd9d2e0d8a39a
linuxlinux>= 1e2fd202f8593985cdadca32e0c322f98e7fe7cb < de203da734fae00e75be50220ba5391e7beecdf9de203da734fae00e75be50220ba5391e7beecdf9
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-142.1525.15.0-142.152
linuxlinux_kernel>= 0 < 6.8.0-86.876.8.0-86.87
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 0 < 5.4.0-218.2385.4.0-218.238
linuxlinux_kernel>= 4.16 < 5.4.2925.4.292
linuxlinux_kernel>= 5.11 < 5.15.1805.15.180
linuxlinux_kernel>= 5.16 < 6.1.1346.1.134
linuxlinux_kernel>= 5.5 < 5.10.2365.10.236
linuxlinux_kernel>= 6.13 < 6.13.116.13.11

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_msrc6.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.