CVE-2023-53272Out-of-bounds Read in Linux

Severity
7.1HIGHNVD
EPSS
0.0%
top 95.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 16

Description

In the Linux kernel, the following vulnerability has been resolved: net: ena: fix shift-out-of-bounds in exponential backoff The ENA adapters on our instances occasionally reset. Once recently logged a UBSAN failure to console in the process: UBSAN: shift-out-of-bounds in build/linux/drivers/net/ethernet/amazon/ena/ena_com.c:540:13 shift exponent 32 is too large for 32-bit type 'unsigned int' CPU: 28 PID: 70012 Comm: kworker/u72:2 Kdump: loaded not tainted 5.15.117 Hardware name: Amazon EC2 c

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages4 packages

NVDlinux/linux_kernel5.85.10.188+4
Debianlinux/linux_kernel< 5.10.191-1+3
CVEListV5linux/linux4bb7f4cf60e38a00965d22aa5979ab143193d41f1e760b2d18bf129b3da052c2946c02758e97d15e+5
debiandebian/linux< linux 6.1.52-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7cp5-c68m-6w8h: In the Linux kernel, the following vulnerability has been resolved: net: ena: fix shift-out-of-bounds in exponential backoff The ENA adapters on our2025-09-16
OSV
CVE-2023-53272: In the Linux kernel, the following vulnerability has been resolved: net: ena: fix shift-out-of-bounds in exponential backoff The ENA adapters on our i2025-09-16

📋Vendor Advisories

2
Red Hat
kernel: net: ena: fix shift-out-of-bounds in exponential backoff2025-09-16
Debian
CVE-2023-53272: linux - In the Linux kernel, the following vulnerability has been resolved: net: ena: f...2023
CVE-2023-53272 — Out-of-bounds Read in Linux | cvebase