CVE-2023-53676Out-of-bounds Write in Linux

Severity
7.8HIGHNVD
EPSS
0.0%
top 96.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 7

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix buffer overflow in lio_target_nacl_info_show() The function lio_target_nacl_info_show() uses sprintf() in a loop to print details for every iSCSI connection in a session without checking for the buffer length. With enough iSCSI connections it's possible to overflow the buffer provided by configfs and corrupt the memory. This patch replaces sprintf() with sysfs_emit_at() that checks for buffer boundrie

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

NVDlinux/linux_kernel3.14.14.326+6
Debianlinux/linux_kernel< 5.10.197-1+3
CVEListV5linux/linuxe48354ce078c079996f89d715dfa44814b4eba01df349e84c2cb0dd05d98c8e1189c26ab4b116083+8
debiandebian/linux< linux 6.1.55-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2023-53676: In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix buffer overflow in lio_target_nacl_info_show() The functi2025-10-07
GHSA
GHSA-4832-crwv-4gfx: In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix buffer overflow in lio_target_nacl_info_show() The func2025-10-07

📋Vendor Advisories

2
Red Hat
kernel: scsi: target: iscsi: Fix buffer overflow in lio_target_nacl_info_show()2025-10-07
Debian
CVE-2023-53676: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: targe...2023