cbcvebase.
CVE-2023-53265
published 2025-09-16

CVE-2023-53265: In the Linux kernel, the following vulnerability has been resolved: ubi: ensure that VID header offset + VID header size __dump_stack lib/dump_stack.c:88…

PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.15%
4.8th percentile
In the Linux kernel, the following vulnerability has been resolved: ubi: ensure that VID header offset + VID header size __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x85/0xad lib/dump_stack.c:106 print_address_description mm/kasan/report.c:317 [inline] print_report.cold.13+0xb6/0x6bb mm/kasan/report.c:433 kasan_report+0xa7/0x11b mm/kasan/report.c:495 crc32_body lib/crc32.c:111 [inline] crc32_le_generic lib/crc32.c:179 [inline] crc32_le_base+0x58c/0x626 lib/crc32.c:197 ubi_io_write_vid_hdr+0x1b7/0x472 drivers/mtd/ubi/io.c:1067 create_vtbl+0x4d5/0x9c4 drivers/mtd/ubi/vtbl.c:317 create_empty_lvol drivers/mtd/ubi/vtbl.c:500 [inline] ubi_read_volume_table+0x67b/0x288a drivers/mtd/ubi/vtbl.c:812 ubi_attach+0xf34/0x1603 drivers/mtd/ubi/attach.c:1601 ubi_attach_mtd_dev+0x6f3/0x185e drivers/mtd/ubi/build.c:965 ctrl_cdev_ioctl+0x2db/0x347 drivers/mtd/ubi/cdev.c:1043 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:870 [inline] __se_sys_ioctl fs/ioctl.c:856 [inline] __x64_sys_ioctl+0x193/0x213 fs/ioctl.c:856 do_syscall_x64 arch/x86/entry/common.c:50 [inline] do_syscall_64+0x3e/0x86 arch/x86/entry/common.c:80 entry_SYSCALL_64_after_hwframe+0x63/0x0 RIP: 0033:0x7f96d5cf753d Code: RSP: 002b:00007fffd72206f8 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f96d5cf753d RDX: 0000000020000080 RSI: 0000000040186f40 RDI: 0000000000000003 RBP: 0000000000400cd0 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000400be0 R13: 00007fffd72207e0 R14: 0000000000000000 R15: 0000000000000000 Allocated by task 1555: kasan_save_stack+0x20/0x3d mm/kasan/common.c:38 kasan_set_track mm/kasan/common.c:45 [inline] set_alloc_info mm/kasan/common.c:437 [inline] ____kasan_kmalloc mm/kasan/common.c:516 [inline] __kasan_kmalloc+0x88/0xa3 mm/kasan/common.c:525 kasan_kmalloc include/linux/kasan.h:234 [inline] __kmalloc+0x138/0x257 mm/slub.c:4429 kmalloc include/linux/slab.h:605 [inline

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.20-1 (bookworm)linux 6.1.20-1 (bookworm)
linuxlinux
linuxlinux>= 801c135ce73d5df1caf3eca35b66a10824ae0707 < 61e04db3bec87f7dd10074296deb7d083e2ccade61e04db3bec87f7dd10074296deb7d083e2ccade
linuxlinux>= 801c135ce73d5df1caf3eca35b66a10824ae0707 < 771e207a839a29ba943e89f473b0fecd16089e2e771e207a839a29ba943e89f473b0fecd16089e2e
linuxlinux>= 801c135ce73d5df1caf3eca35b66a10824ae0707 < f7adb740f97b6fa84e658892dcb08e37a31a4e77f7adb740f97b6fa84e658892dcb08e37a31a4e77
linuxlinux>= 801c135ce73d5df1caf3eca35b66a10824ae0707 < 846bfba34175c23b13cc2023c2d67b96e8c14c43846bfba34175c23b13cc2023c2d67b96e8c14c43
linuxlinux>= 801c135ce73d5df1caf3eca35b66a10824ae0707 < 701bb3ed5a88a73ebbe1266895bdeff065226dca701bb3ed5a88a73ebbe1266895bdeff065226dca
linuxlinux>= 801c135ce73d5df1caf3eca35b66a10824ae0707 < 61aeba0e4b4124cfe3c5427feaf29c626dfa89e561aeba0e4b4124cfe3c5427feaf29c626dfa89e5
linuxlinux>= 801c135ce73d5df1caf3eca35b66a10824ae0707 < e1b73fe4f4c6bb80755eb4bf4b867a8fd8b1a7fee1b73fe4f4c6bb80755eb4bf4b867a8fd8b1a7fe
linuxlinux>= 801c135ce73d5df1caf3eca35b66a10824ae0707 < 1b42b1a36fc946f0d7088425b90d491b4257ca3e1b42b1a36fc946f0d7088425b90d491b4257ca3e
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 2.6.22 < 4.14.3084.14.308
linuxlinux_kernel>= 4.15 < 4.19.2764.19.276
linuxlinux_kernel>= 4.20 < 5.4.2355.4.235
linuxlinux_kernel>= 5.11 < 5.15.1005.15.100
linuxlinux_kernel>= 5.16 < 6.1.186.1.18
linuxlinux_kernel>= 5.5 < 5.10.1735.10.173
linuxlinux_kernel>= 6.2 < 6.2.56.2.5

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.