cbcvebase.
CVE-2023-53108
published 2025-05-02

CVE-2023-53108: In the Linux kernel, the following vulnerability has been resolved: net/iucv: Fix size of interrupt data iucv_irq_data needs to be 4 bytes larger. These bytes…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.8th percentile
In the Linux kernel, the following vulnerability has been resolved: net/iucv: Fix size of interrupt data iucv_irq_data needs to be 4 bytes larger. These bytes are not used by the iucv module, but written by the z/VM hypervisor in case a CPU is deconfigured. Reported as: BUG dma-kmalloc-64 (Not tainted): kmalloc Redzone overwritten 0x0000000000400564-0x0000000000400567 @offset=1380. First byte 0x80 instead of 0xcc Allocated in iucv_cpu_prepare+0x44/0xd0 age=167839 cpu=2 pid=1 __kmem_cache_alloc_node+0x166/0x450 kmalloc_node_trace+0x3a/0x70 iucv_cpu_prepare+0x44/0xd0 cpuhp_invoke_callback+0x156/0x2f0 cpuhp_issue_call+0xf0/0x298 __cpuhp_setup_state_cpuslocked+0x136/0x338 __cpuhp_setup_state+0xf4/0x288 iucv_init+0xf4/0x280 do_one_initcall+0x78/0x390 do_initcalls+0x11a/0x140 kernel_init_freeable+0x25e/0x2a0 kernel_init+0x2e/0x170 __ret_from_fork+0x3c/0x58 ret_from_fork+0xa/0x40 Freed in iucv_init+0x92/0x280 age=167839 cpu=2 pid=1 __kmem_cache_free+0x308/0x358 iucv_init+0x92/0x280 do_one_initcall+0x78/0x390 do_initcalls+0x11a/0x140 kernel_init_freeable+0x25e/0x2a0 kernel_init+0x2e/0x170 __ret_from_fork+0x3c/0x58 ret_from_fork+0xa/0x40 Slab 0x0000037200010000 objects=32 used=30 fp=0x0000000000400640 flags=0x1ffff00000010200(slab|head|node=0|zone=0| Object 0x0000000000400540 @offset=1344 fp=0x0000000000000000 Redzone 0000000000400500: cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc ................ Redzone 0000000000400510: cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc ................ Redzone 0000000000400520: cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc ................ Redzone 0000000000400530: cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc ................ Object 0000000000400540: 00 01 00 03 00 00 00 00 00 00 00 00 00 00 00 00 ................ Object 0000000000400550: f3 86 81 f2 f4 82 f8 82 f0 f0 f0 f0 f0 f0 f0 f2 ................ Object 0000000000400560: 00 00 00 00 80 00 00 00 cc cc cc cc cc cc cc cc ................ Object 0000000000400570: cc cc cc cc cc

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.25-1 (bookworm)linux 6.1.25-1 (bookworm)
linuxlinux
linuxlinux>= 2356f4cb191100a5e92d537f13e5efdbc697e9cb < a908eae0f71811afee86be7088692f1aa5855c3ba908eae0f71811afee86be7088692f1aa5855c3b
linuxlinux>= 2356f4cb191100a5e92d537f13e5efdbc697e9cb < b0d2bb5e31a693ebc8888eb407f8a257a3680efab0d2bb5e31a693ebc8888eb407f8a257a3680efa
linuxlinux>= 2356f4cb191100a5e92d537f13e5efdbc697e9cb < 71da5991b6438ad6da13ceb25465ee2760a1c52f71da5991b6438ad6da13ceb25465ee2760a1c52f
linuxlinux>= 2356f4cb191100a5e92d537f13e5efdbc697e9cb < bd2e78462ae18484e55ae4d285df2c86b86bdd12bd2e78462ae18484e55ae4d285df2c86b86bdd12
linuxlinux>= 2356f4cb191100a5e92d537f13e5efdbc697e9cb < 3cfdefdaaa4b2a77e84d0db5e0a47a7aa3bb615a3cfdefdaaa4b2a77e84d0db5e0a47a7aa3bb615a
linuxlinux>= 2356f4cb191100a5e92d537f13e5efdbc697e9cb < c78f1345db4e4b3b78f9b768f4074ebd60abe966c78f1345db4e4b3b78f9b768f4074ebd60abe966
linuxlinux>= 2356f4cb191100a5e92d537f13e5efdbc697e9cb < 93a970494881004c348d8feb38463ee72496e99a93a970494881004c348d8feb38463ee72496e99a
linuxlinux>= 2356f4cb191100a5e92d537f13e5efdbc697e9cb < 3d87debb8ed2649608ff432699e7c961c0c6f03b3d87debb8ed2649608ff432699e7c961c0c6f03b
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 2.6.21 < 4.14.3114.14.311
linuxlinux_kernel>= 4.15 < 4.19.2794.19.279
linuxlinux_kernel>= 4.20 < 5.4.2385.4.238
linuxlinux_kernel>= 5.11 < 5.15.1045.15.104
linuxlinux_kernel>= 5.16 < 6.1.216.1.21
linuxlinux_kernel>= 5.5 < 5.10.1765.10.176
linuxlinux_kernel>= 6.2 < 6.2.86.2.8

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.