cbcvebase.
CVE-2023-53400
published 2025-09-18

CVE-2023-53400: In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: Fix Oops by 9.1 surround channel names get_line_out_pfx() may trigger an Oops by…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.4th percentile
In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: Fix Oops by 9.1 surround channel names get_line_out_pfx() may trigger an Oops by overflowing the static array with more than 8 channels. This was reported for MacBookPro 12,1 with Cirrus codec. As a workaround, extend for the 9.1 channels and also fix the potential Oops by unifying the code paths accessing the same array with the proper size check.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.37-1 (bookworm)linux 6.1.37-1 (bookworm)
linuxlinux
linuxlinux>= 247d85ee068610c50d66ee0cd3130e02c69f5f2e < 082dcd51667b29097500c824c37f24da997a6a8a082dcd51667b29097500c824c37f24da997a6a8a
linuxlinux>= 247d85ee068610c50d66ee0cd3130e02c69f5f2e < b5694aae4c2d9a288bafce7d38f122769e0428e6b5694aae4c2d9a288bafce7d38f122769e0428e6
linuxlinux>= 247d85ee068610c50d66ee0cd3130e02c69f5f2e < 4ef155ddf9578bf035964d58739fdcd7dd44b4a44ef155ddf9578bf035964d58739fdcd7dd44b4a4
linuxlinux>= 247d85ee068610c50d66ee0cd3130e02c69f5f2e < 546b1f5f45a355ae0d3a8041cdaca597dfcac825546b1f5f45a355ae0d3a8041cdaca597dfcac825
linuxlinux>= 247d85ee068610c50d66ee0cd3130e02c69f5f2e < e8c7d7c43d5edd20e518fe1dfb2371d1fe6e8bb8e8c7d7c43d5edd20e518fe1dfb2371d1fe6e8bb8
linuxlinux>= 247d85ee068610c50d66ee0cd3130e02c69f5f2e < dc8c569d59f17b17d7bca4f68c36bd571659921edc8c569d59f17b17d7bca4f68c36bd571659921e
linuxlinux>= 247d85ee068610c50d66ee0cd3130e02c69f5f2e < fcf637461019e9a5a0c12fc5c42a9db1779b0634fcf637461019e9a5a0c12fc5c42a9db1779b0634
linuxlinux>= 247d85ee068610c50d66ee0cd3130e02c69f5f2e < 3b44ec8c5c44790a82f07e90db45643c762878c63b44ec8c5c44790a82f07e90db45643c762878c6
linuxlinux_kernel< 4.14.3164.14.316
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.37-16.1.37-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 4.15 < 4.19.2844.19.284
linuxlinux_kernel>= 4.20 < 5.4.2445.4.244
linuxlinux_kernel>= 5.11 < 5.15.1135.15.113
linuxlinux_kernel>= 5.16 < 6.1.306.1.30
linuxlinux_kernel>= 5.5 < 5.10.1815.10.181
linuxlinux_kernel>= 6.2 < 6.3.46.3.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.