CVE-2023-53607
published 2025-10-04CVE-2023-53607: In the Linux kernel, the following vulnerability has been resolved: ALSA: ymfpci: Fix BUG_ON in probe function The snd_dma_buffer.bytes field now contains the…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
4.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
ALSA: ymfpci: Fix BUG_ON in probe function
The snd_dma_buffer.bytes field now contains the aligned size, which this
snd_BUG_ON() did not account for, resulting in the following:
[ 9.625915] ------------[ cut here ]------------
[ 9.633440] WARNING: CPU: 0 PID: 126 at sound/pci/ymfpci/ymfpci_main.c:2168 snd_ymfpci_create+0x681/0x698 [snd_ymfpci]
[ 9.648926] Modules linked in: snd_ymfpci(+) snd_intel_dspcfg kvm(+) snd_intel_sdw_acpi snd_ac97_codec snd_mpu401_uart snd_opl3_lib irqbypass snd_hda_codec gameport snd_rawmidi crct10dif_pclmul crc32_pclmul cfg80211 snd_hda_core polyval_clmulni polyval_generic gf128mul snd_seq_device ghash_clmulni_intel snd_hwdep ac97_bus sha512_ssse3 rfkill snd_pcm aesni_intel tg3 snd_timer crypto_simd snd mxm_wmi libphy cryptd k10temp fam15h_power pcspkr soundcore sp5100_tco wmi acpi_cpufreq mac_hid dm_multipath sg loop fuse dm_mod bpf_preload ip_tables x_tables ext4 crc32c_generic crc16 mbcache jbd2 sr_mod cdrom ata_generic pata_acpi firewire_ohci crc32c_intel firewire_core xhci_pci crc_itu_t pata_via xhci_pci_renesas floppy
[ 9.711849] CPU: 0 PID: 126 Comm: kworker/0:2 Not tainted 6.1.21-1-lts #1 08d2e5ece03136efa7c6aeea9a9c40916b1bd8da
[ 9.722200] Hardware name: To Be Filled By O.E.M. To Be Filled By O.E.M./990FX Extreme4, BIOS P2.70 06/05/2014
[ 9.732204] Workqueue: events work_for_cpu_fn
[ 9.736580] RIP: 0010:snd_ymfpci_create+0x681/0x698 [snd_ymfpci]
[ 9.742594] Code: 8c c0 4c 89 e2 48 89 df 48 c7 c6 92 c6 8c c0 e8 15 d0 e9 ff 48 83 c4 08 44 89 e8 5b 5d 41 5c 41 5d 41 5e 41 5f e9 d3 7a 33 e3 0b e9 cb fd ff ff 41 bd fb ff ff ff eb db 41 bd f4 ff ff ff eb
[ 9.761358] RSP: 0018:ffffab64804e7da0 EFLAGS: 00010287
[ 9.766594] RAX: ffff8fa2df06c400 RBX: ffff8fa3073a8000 RCX: ffff8fa303fbc4a8
[ 9.773734] RDX: ffff8fa2df06d000 RSI: 0000000000000010 RDI: 0000000000000020
[ 9.780876] RBP: ffff8fa300b5d0d0 R08: ffff8fa3073a8e50 R09: 00000000df06bf00
[ 9.788018] R10: ffff8fa2df0
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.25-1 (bookworm) | linux 6.1.25-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 4.14.290 < 4.15 | 4.15 |
| linux | linux | >= 4.19.254 < 4.20 | 4.20 |
| linux | linux | >= 4.9.325 < 4.10 | 4.10 |
| linux | linux | >= 4faf4bbc2d600a921052ff45b1b5914d583d9046 < 96e34c88000febc83e41aa7db0b0a41676314818 | 96e34c88000febc83e41aa7db0b0a41676314818 |
| linux | linux | >= 5.10.134 < 5.10.177 | 5.10.177 |
| linux | linux | >= 5.4.208 < 5.5 | 5.5 |
| linux | linux | >= 5c1733e33c888a3cb7f576564d8ad543d5ad4a9e < 81d2a7e93c8322ca6b858f6736d7fc3d034e6c23 | 81d2a7e93c8322ca6b858f6736d7fc3d034e6c23 |
| linux | linux | >= 5c1733e33c888a3cb7f576564d8ad543d5ad4a9e < 32b9bd7cfc2e2d92d595386add4e111b232b351f | 32b9bd7cfc2e2d92d595386add4e111b232b351f |
| linux | linux | >= 5c1733e33c888a3cb7f576564d8ad543d5ad4a9e < d0217b09910c081b6471181345ea5b24025edf51 | d0217b09910c081b6471181345ea5b24025edf51 |
| linux | linux | >= 5c1733e33c888a3cb7f576564d8ad543d5ad4a9e < 6be2e7522eb529b41c16d459f33bbdbcddbf5c15 | 6be2e7522eb529b41c16d459f33bbdbcddbf5c15 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 4.14.290 < 4.15 | 4.15 |
| linux | linux_kernel | >= 4.19.254 < 4.20 | 4.20 |
| linux | linux_kernel | >= 4.9.325 < 4.10 | 4.10 |
| linux | linux_kernel | >= 5.10.134 < 5.10.177 | 5.10.177 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 5.10.176/5.15.105/6.1.22/6.2.9 ALSA ymfpci_main.c snd_BUG_ON buffer overflow (EUVD-2023-60001 / WID-SEC-2025-2194)
vuldb·2026-04-28·CVSS 5.5
CVE-2023-53607 [MEDIUM] Linux Kernel up to 5.10.176/5.15.105/6.1.22/6.2.9 ALSA ymfpci_main.c snd_BUG_ON buffer overflow (EUVD-2023-60001 / WID-SEC-2025-2194)
A vulnerability categorized as critical has been discovered in Linux Kernel up to 5.10.176/5.15.105/6.1.22/6.2.9. This impacts the function snd_BUG_ON of the file sound/pci/ymfpci/ymfpci_main.c of the component ALSA. Executing a manipulation can lead to buffer overflow.
This vulnerability is registered as CVE-2023-53607. The attack requires access to the local network. No exploit is available.
It is advisable to upgrade the affected component.
GHSA
GHSA-mj42-qmqq-f53f: In the Linux kernel, the following vulnerability has been resolved:
ALSA: ymfpci: Fix BUG_ON in probe function
The snd_dma_buffer
ghsa_unreviewed·2025-10-04
CVE-2023-53607 [MEDIUM] CWE-617 GHSA-mj42-qmqq-f53f: In the Linux kernel, the following vulnerability has been resolved:
ALSA: ymfpci: Fix BUG_ON in probe function
The snd_dma_buffer
In the Linux kernel, the following vulnerability has been resolved:
ALSA: ymfpci: Fix BUG_ON in probe function
The snd_dma_buffer.bytes field now contains the aligned size, which this
snd_BUG_ON() did not account for, resulting in the following:
[ 9.625915] ------------[ cut here ]------------
[ 9.633440] WARNING: CPU: 0 PID: 126 at sound/pci/ymfpci/ymfpci_main.c:2168 snd_ymfpci_create+0x681/0x698 [snd_ymfpci]
[ 9.648926] Modules linked in: snd_ymfpci(+) snd_intel_dspcfg kvm(+) snd_intel_sdw_acpi snd_ac97_codec snd_mpu401_uart snd_opl3_lib irqbypass snd_hda_codec gameport snd_rawmidi crct10dif_pclmul crc32_pclmul cfg80211 snd_hda_core polyval_clmulni polyval_generic gf128mul snd_seq_device ghash_clmulni_intel snd_hwdep ac97_bus sha512_ssse3 rfkill snd_pcm aesni_intel tg3 snd_timer crypt
OSV
CVE-2023-53607: In the Linux kernel, the following vulnerability has been resolved: ALSA: ymfpci: Fix BUG_ON in probe function The snd_dma_buffer
osv·2025-10-04·CVSS 5.5
CVE-2023-53607 [MEDIUM] CVE-2023-53607: In the Linux kernel, the following vulnerability has been resolved: ALSA: ymfpci: Fix BUG_ON in probe function The snd_dma_buffer
In the Linux kernel, the following vulnerability has been resolved: ALSA: ymfpci: Fix BUG_ON in probe function The snd_dma_buffer.bytes field now contains the aligned size, which this snd_BUG_ON() did not account for, resulting in the following: [ 9.625915] ------------[ cut here ]------------ [ 9.633440] WARNING: CPU: 0 PID: 126 at sound/pci/ymfpci/ymfpci_main.c:2168 snd_ymfpci_create+0x681/0x698 [snd_ymfpci] [ 9.648926] Modules linked in: snd_ymfpci(+) snd_intel_dspcfg kvm(+) snd_intel_sdw_acpi snd_ac97_codec snd_mpu401_uart snd_opl3_lib irqbypass snd_hda_codec gameport snd_rawmidi crct10dif_pclmul crc32_pclmul cfg80211 snd_hda_core polyval_clmulni polyval_generic gf128mul snd_seq_device ghash_clmulni_intel snd_hwdep ac97_bus sha512_ssse3 rfkill snd_pcm aesni_intel tg3 snd_timer crypto_s
Red Hat
kernel: ALSA: ymfpci: Fix BUG_ON in probe function
vendor_redhat·2025-10-04·CVSS 5.5
CVE-2023-53607 [MEDIUM] CWE-131 kernel: ALSA: ymfpci: Fix BUG_ON in probe function
kernel: ALSA: ymfpci: Fix BUG_ON in probe function
In the Linux kernel, the following vulnerability has been resolved:
ALSA: ymfpci: Fix BUG_ON in probe function
The snd_dma_buffer.bytes field now contains the aligned size, which this
snd_BUG_ON() did not account for, resulting in the following:
[ 9.625915] ------------[ cut here ]------------
[ 9.633440] WARNING: CPU: 0 PID: 126 at sound/pci/ymfpci/ymfpci_main.c:2168 snd_ymfpci_create+0x681/0x698 [snd_ymfpci]
[ 9.648926] Modules linked in: snd_ymfpci(+) snd_intel_dspcfg kvm(+) snd_intel_sdw_acpi snd_ac97_codec snd_mpu401_uart snd_opl3_lib irqbypass snd_hda_codec gameport snd_rawmidi crct10dif_pclmul crc32_pclmul cfg80211 snd_hda_core polyval_clmulni polyval_generic gf128mul snd_seq_device ghash_clmulni_intel snd_hwdep ac97_bus sha512_sss
Debian
CVE-2023-53607: linux - In the Linux kernel, the following vulnerability has been resolved: ALSA: ymfpc...
vendor_debian·2023·CVSS 5.5
CVE-2023-53607 [MEDIUM] CVE-2023-53607: linux - In the Linux kernel, the following vulnerability has been resolved: ALSA: ymfpc...
In the Linux kernel, the following vulnerability has been resolved: ALSA: ymfpci: Fix BUG_ON in probe function The snd_dma_buffer.bytes field now contains the aligned size, which this snd_BUG_ON() did not account for, resulting in the following: [ 9.625915] ------------[ cut here ]------------ [ 9.633440] WARNING: CPU: 0 PID: 126 at sound/pci/ymfpci/ymfpci_main.c:2168 snd_ymfpci_create+0x681/0x698 [snd_ymfpci] [ 9.648926] Modules linked in: snd_ymfpci(+) snd_intel_dspcfg kvm(+) snd_intel_sdw_acpi snd_ac97_codec snd_mpu401_uart snd_opl3_lib irqbypass snd_hda_codec gameport snd_rawmidi crct10dif_pclmul crc32_pclmul cfg80211 snd_hda_core polyval_clmulni polyval_generic gf128mul snd_seq_device ghash_clmulni_intel snd_hwdep ac97_bus sha512_ssse3 rfkill snd_pcm aesni_intel tg3 snd_timer crypto_s
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/32b9bd7cfc2e2d92d595386add4e111b232b351fhttps://git.kernel.org/stable/c/6be2e7522eb529b41c16d459f33bbdbcddbf5c15https://git.kernel.org/stable/c/81d2a7e93c8322ca6b858f6736d7fc3d034e6c23https://git.kernel.org/stable/c/96e34c88000febc83e41aa7db0b0a41676314818https://git.kernel.org/stable/c/d0217b09910c081b6471181345ea5b24025edf51
2025-10-04
Published