Severity
6.7MEDIUMNVD
EPSS
0.0%
top 97.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 21
Latest updateNov 8

Description

A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. Only privileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unrelated kernel memory, causing random kernel crashes and memory corruption.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages0 packages

Also affects: Fedora 38

🔴Vulnerability Details

4
Kernel
nvme-pci: use sgls for all user requests if possible2024-11-08
GHSA
GHSA-2j83-334m-g9w4: A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel2023-11-21
OSV
CVE-2023-6238: A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel2023-11-21
CVEList
Kernel: nvme: memory corruption via unprivileged user passthrough2023-11-21

📋Vendor Advisories

2
Red Hat
kernel: nvme: memory corruption via unprivileged user passthrough2023-10-13
Debian
CVE-2023-6238: linux - A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in th...2023

💬Community

1
Bugzilla
CVE-2023-6238 kernel: nvme: memory corruption via unprivileged user passthrough2023-11-21
CVE-2023-6238 — Classic Buffer Overflow in Fedora | cvebase