cbcvebase.
CVE-2023-53661
published 2025-10-07

CVE-2023-53661: In the Linux kernel, the following vulnerability has been resolved: bnxt: avoid overflow in bnxt_get_nvram_directory() The value of an arithmetic expression is…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
4.2th percentile
In the Linux kernel, the following vulnerability has been resolved: bnxt: avoid overflow in bnxt_get_nvram_directory() The value of an arithmetic expression is subject of possible overflow due to a failure to cast operands to a larger data type before performing arithmetic. Used macro for multiplication instead operator for avoiding overflow. Found by Security Code and Linux Verification Center (linuxtesting.org) with SVACE.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.37-1 (bookworm)linux 6.1.37-1 (bookworm)
linuxlinux
linuxlinux>= c0c050c58d840994ba842ad1c338a98e7c12b764 < d5eaf2a6b077f32a477feb1e9e1c1f60605b460ed5eaf2a6b077f32a477feb1e9e1c1f60605b460e
linuxlinux>= c0c050c58d840994ba842ad1c338a98e7c12b764 < efb1a257513438d43f4335f09b2f684e8167cad2efb1a257513438d43f4335f09b2f684e8167cad2
linuxlinux>= c0c050c58d840994ba842ad1c338a98e7c12b764 < 17e0453a7523ad7a25bb47af941b150a6c66d7b617e0453a7523ad7a25bb47af941b150a6c66d7b6
linuxlinux>= c0c050c58d840994ba842ad1c338a98e7c12b764 < 7c6dddc239abe660598c49ec95ea0ed6399a4b2a7c6dddc239abe660598c49ec95ea0ed6399a4b2a
linuxlinux_kernel>= 0 < 6.1.37-16.1.37-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 4.4 < 5.15.1135.15.113
linuxlinux_kernel>= 5.16 < 6.1.306.1.30
linuxlinux_kernel>= 6.2 < 6.3.46.3.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.