CVE-2023-53598
published 2025-10-04CVE-2023-53598: In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Range check CHDBOFF and ERDBOFF If the value read from the CHDBOFF and…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
bus: mhi: host: Range check CHDBOFF and ERDBOFF
If the value read from the CHDBOFF and ERDBOFF registers is outside the
range of the MHI register space then an invalid address might be computed
which later causes a kernel panic. Range check the read value to prevent
a crash due to bad data from the device.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.37-1 (bookworm) | linux 6.1.37-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 6cd330ae76ffd5c8f6294c423cabde7eeef1b40c < 372f1752b74572b0a9d2288841eab7db17daccae | 372f1752b74572b0a9d2288841eab7db17daccae |
| linux | linux | >= 6cd330ae76ffd5c8f6294c423cabde7eeef1b40c < 2343385fe6eed11d0432ab42a97b3ca4aef06a99 | 2343385fe6eed11d0432ab42a97b3ca4aef06a99 |
| linux | linux | >= 6cd330ae76ffd5c8f6294c423cabde7eeef1b40c < a2cbb1a45a0c86ce77839c0875414efe1a89315e | a2cbb1a45a0c86ce77839c0875414efe1a89315e |
| linux | linux | >= 6cd330ae76ffd5c8f6294c423cabde7eeef1b40c < 83bf6b87e2dd053d95d89eb2f01ae885f9e568db | 83bf6b87e2dd053d95d89eb2f01ae885f9e568db |
| linux | linux | >= 6cd330ae76ffd5c8f6294c423cabde7eeef1b40c < 4e584127ec2bd42a37c88badb49df409f21fa40a | 4e584127ec2bd42a37c88badb49df409f21fa40a |
| linux | linux | >= 6cd330ae76ffd5c8f6294c423cabde7eeef1b40c < 6a0c637bfee69a74c104468544d9f2a6579626d0 | 6a0c637bfee69a74c104468544d9f2a6579626d0 |
| linux | linux_kernel | >= 0 < 5.10.197-1 | 5.10.197-1 |
| linux | linux_kernel | >= 0 < 6.1.37-1 | 6.1.37-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 5.11 < 5.15.112 | 5.15.112 |
| linux | linux_kernel | >= 5.16 < 6.1.28 | 6.1.28 |
| linux | linux_kernel | >= 5.7 < 5.10.192 | 5.10.192 |
| linux | linux_kernel | >= 6.2 < 6.2.15 | 6.2.15 |
| linux | linux_kernel | >= 6.3 < 6.3.2 | 6.3.2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.3.1 bus denial of service (EUVD-2023-60010 / WID-SEC-2025-2194)
vuldb·2026-04-28·CVSS 5.5
CVE-2023-53598 [MEDIUM] Linux Kernel up to 6.3.1 bus denial of service (EUVD-2023-60010 / WID-SEC-2025-2194)
A vulnerability marked as critical has been reported in Linux Kernel up to 5.10.191/5.15.111/6.1.27/6.2.14/6.3.1. This impacts an unknown function of the component bus. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2023-53598. Access to the local network is required for this attack to succeed. There is no exploit available.
It is suggested to upgrade the affected component.
OSV
CVE-2023-53598: In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Range check CHDBOFF and ERDBOFF If the value read from the CHDBOFF
osv·2025-10-04·CVSS 5.5
CVE-2023-53598 [MEDIUM] CVE-2023-53598: In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Range check CHDBOFF and ERDBOFF If the value read from the CHDBOFF
In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Range check CHDBOFF and ERDBOFF If the value read from the CHDBOFF and ERDBOFF registers is outside the range of the MHI register space then an invalid address might be computed which later causes a kernel panic. Range check the read value to prevent a crash due to bad data from the device.
GHSA
GHSA-mm9q-jx75-m4x6: In the Linux kernel, the following vulnerability has been resolved:
bus: mhi: host: Range check CHDBOFF and ERDBOFF
If the value read from the CHDBO
ghsa_unreviewed·2025-10-04
CVE-2023-53598 [MEDIUM] GHSA-mm9q-jx75-m4x6: In the Linux kernel, the following vulnerability has been resolved:
bus: mhi: host: Range check CHDBOFF and ERDBOFF
If the value read from the CHDBO
In the Linux kernel, the following vulnerability has been resolved:
bus: mhi: host: Range check CHDBOFF and ERDBOFF
If the value read from the CHDBOFF and ERDBOFF registers is outside the
range of the MHI register space then an invalid address might be computed
which later causes a kernel panic. Range check the read value to prevent
a crash due to bad data from the device.
Red Hat
kernel: bus: mhi: host: Range check CHDBOFF and ERDBOFF
vendor_redhat·2025-10-04·CVSS 5.5
CVE-2023-53598 [MEDIUM] CWE-787 kernel: bus: mhi: host: Range check CHDBOFF and ERDBOFF
kernel: bus: mhi: host: Range check CHDBOFF and ERDBOFF
In the Linux kernel, the following vulnerability has been resolved:
bus: mhi: host: Range check CHDBOFF and ERDBOFF
If the value read from the CHDBOFF and ERDBOFF registers is outside the
range of the MHI register space then an invalid address might be computed
which later causes a kernel panic. Range check the read value to prevent
a crash due to bad data from the device.
A missing bounds check flaw was found in the Linux kernel's Modem Host Interface bus driver in the channel doorbell offset validation logic.
A local user can trigger this issue on systems with MHI devices (typically Qualcomm modems or wireless cards) by using a device that provides malformed or malicious channel configuration data during initialization, causing an
Debian
CVE-2023-53598: linux - In the Linux kernel, the following vulnerability has been resolved: bus: mhi: h...
vendor_debian·2023·CVSS 5.5
CVE-2023-53598 [MEDIUM] CVE-2023-53598: linux - In the Linux kernel, the following vulnerability has been resolved: bus: mhi: h...
In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Range check CHDBOFF and ERDBOFF If the value read from the CHDBOFF and ERDBOFF registers is outside the range of the MHI register space then an invalid address might be computed which later causes a kernel panic. Range check the read value to prevent a crash due to bad data from the device.
Scope: local
bookworm: resolved (fixed in 6.1.37-1)
bullseye: resolved (fixed in 5.10.197-1)
forky: resolved (fixed in 6.3.7-1)
sid: resolved (fixed in 6.3.7-1)
trixie: resolved (fixed in 6.3.7-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/2343385fe6eed11d0432ab42a97b3ca4aef06a99https://git.kernel.org/stable/c/372f1752b74572b0a9d2288841eab7db17daccaehttps://git.kernel.org/stable/c/4e584127ec2bd42a37c88badb49df409f21fa40ahttps://git.kernel.org/stable/c/6a0c637bfee69a74c104468544d9f2a6579626d0https://git.kernel.org/stable/c/83bf6b87e2dd053d95d89eb2f01ae885f9e568dbhttps://git.kernel.org/stable/c/a2cbb1a45a0c86ce77839c0875414efe1a89315e
2025-10-04
Published