cbcvebase.
CVE-2023-53465
published 2025-10-01

CVE-2023-53465: In the Linux kernel, the following vulnerability has been resolved: soundwire: qcom: fix storing port config out-of-bounds The 'qcom_swrm_ctrl->pconfig' has…

PriorityP431high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.16%
6.1th percentile
In the Linux kernel, the following vulnerability has been resolved: soundwire: qcom: fix storing port config out-of-bounds The 'qcom_swrm_ctrl->pconfig' has size of QCOM_SDW_MAX_PORTS (14), however we index it starting from 1, not 0, to match real port numbers. This can lead to writing port config past 'pconfig' bounds and overwriting next member of 'qcom_swrm_ctrl' struct. Reported also by smatch: drivers/soundwire/qcom.c:1269 qcom_swrm_get_port_config() error: buffer overflow 'ctrl->pconfig' 14 <= 14

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
linuxlinux
linuxlinux>= 9916c02ccd74e672b62dd1a9017ac2f237ebf512 < 20f7c4d51c94abb1a1a7c21900db4fb5afe5c8ff20f7c4d51c94abb1a1a7c21900db4fb5afe5c8ff
linuxlinux>= 9916c02ccd74e672b62dd1a9017ac2f237ebf512 < 801daff0078087b5df9145c9f5e643c28129734b801daff0078087b5df9145c9f5e643c28129734b
linuxlinux>= 9916c02ccd74e672b62dd1a9017ac2f237ebf512 < 32eb67d7360d48c15883e0d21b29c0aab9da022e32eb67d7360d48c15883e0d21b29c0aab9da022e
linuxlinux>= 9916c02ccd74e672b62dd1a9017ac2f237ebf512 < 490937d479abe5f6584e69b96df066bc87be92e9490937d479abe5f6584e69b96df066bc87be92e9
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 5.13 < 5.15.1215.15.121
linuxlinux_kernel>= 5.16 < 6.1.406.1.40
linuxlinux_kernel>= 6.2 < 6.4.56.4.5

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.