CVE-2023-53722Out-of-bounds Read in Linux

CWE-125Out-of-bounds Read6 documents5 sources
Severity
4.4MEDIUM
No vector
EPSS
0.0%
top 88.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 22

Description

In the Linux kernel, the following vulnerability has been resolved: md: raid1: fix potential OOB in raid1_remove_disk() If rddev->raid_disk is greater than mddev->raid_disks, there will be an out-of-bounds in raid1_remove_disk(). We have already found similar reports as follows: 1) commit d17f744e883b ("md-raid10: fix KASAN warning") 2) commit 1ebc2cec0b7d ("dm raid: fix KASAN warning in raid5_remove_disk") Fix this bug by checking whether the "number" variable is valid.

Affected Packages4 packages

Linuxlinux/linux_kernel3.3.04.14.326+6
Debianlinux/linux_kernel< 5.10.197-1+3
CVEListV5linux/linuxb8321b68d1445f308324517e45fb0a5c2b48e271beedf40f73939f248c81802eda08a2a8148ea13e+8
debiandebian/linux< linux 6.1.55-1 (bookworm)

🔴Vulnerability Details

3
GHSA
GHSA-564p-3xmp-v9fw: In the Linux kernel, the following vulnerability has been resolved: md: raid1: fix potential OOB in raid1_remove_disk() If rddev->raid_disk is great2025-10-22
OSV
md: raid1: fix potential OOB in raid1_remove_disk()2025-10-22
OSV
CVE-2023-53722: In the Linux kernel, the following vulnerability has been resolved: md: raid1: fix potential OOB in raid1_remove_disk() If rddev->raid_disk is greater2025-10-22

📋Vendor Advisories

2
Red Hat
kernel: md: raid1: fix potential OOB in raid1_remove_disk()2025-10-22
Debian
CVE-2023-53722: linux - In the Linux kernel, the following vulnerability has been resolved: md: raid1: ...2023