cbcvebase.
CVE-2023-54057
published 2025-12-24

CVE-2023-54057: In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Add a length limitation for the ivrs_acpihid command-line parameter The 'acpiid'…

PriorityP429low5.5
EPSS
0.21%
11.8th percentile
In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Add a length limitation for the ivrs_acpihid command-line parameter The 'acpiid' buffer in the parse_ivrs_acpihid function may overflow, because the string specifier in the format string sscanf() has no width limitation. Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with SVACE.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.20-1 (bookworm)linux 6.1.20-1 (bookworm)
linuxlinux
linuxlinux>= ca3bf5d47cec8b7614bcb2e9132c40081d6d81db < 5e97dc748d13fad582136ba0c8cec215c7aeeb175e97dc748d13fad582136ba0c8cec215c7aeeb17
linuxlinux>= ca3bf5d47cec8b7614bcb2e9132c40081d6d81db < f2a5ec7f7b28f9b9cd5fac232ff51019a7f7b9e9f2a5ec7f7b28f9b9cd5fac232ff51019a7f7b9e9
linuxlinux>= ca3bf5d47cec8b7614bcb2e9132c40081d6d81db < c513043e0afe6a8ba79d00af358655afabb576d2c513043e0afe6a8ba79d00af358655afabb576d2
linuxlinux>= ca3bf5d47cec8b7614bcb2e9132c40081d6d81db < 2ae19ac3ea82a5b87a81c10adbb497c9e58bdd602ae19ac3ea82a5b87a81c10adbb497c9e58bdd60
linuxlinux>= ca3bf5d47cec8b7614bcb2e9132c40081d6d81db < 63cd11165e5e0ea2012254c764003eda1f9adb7d63cd11165e5e0ea2012254c764003eda1f9adb7d
linuxlinux>= ca3bf5d47cec8b7614bcb2e9132c40081d6d81db < b6b26d86c61c441144c72f842f7469bb686e1211b6b26d86c61c441144c72f842f7469bb686e1211
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 4.7.0 < 5.4.2375.4.237
linuxlinux_kernel>= 5.11.0 < 5.15.1035.15.103
linuxlinux_kernel>= 5.16.0 < 6.1.166.1.16
linuxlinux_kernel>= 5.5.0 < 5.10.1755.10.175
linuxlinux_kernel>= 6.2.0 < 6.2.36.2.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.