CVE-2023-53019

In the Linux kernel, the following vulnerability has been resolved: net: mdio: validate parameter addr in mdiobus_get_phy() The caller may pass any value as addr, what may result in an out-of-bounds access to array mdio_map. One existing case is stmmac_init_phy() that may pass -1 as addr. Therefore validate addr before using it.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.2:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.2:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.2:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.2:rc4:*:*:*:*:*:*

History

30 Oct 2025, 16:20

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-129
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: net: mdio: validar el parámetro addr en mdiobus_get_phy(). El llamador puede pasar cualquier valor como addr, lo que puede resultar en un acceso fuera de límites a la matriz mdio_map. Un caso existente es stmmac_init_phy(), que puede pasar -1 como addr. Por lo tanto, valide addr antes de usarlo.
First Time Linux linux Kernel
Linux
References () https://git.kernel.org/stable/c/1d80c259dfbadefa61b7ea334dfce5cb57f8c72f - () https://git.kernel.org/stable/c/1d80c259dfbadefa61b7ea334dfce5cb57f8c72f - Patch
References () https://git.kernel.org/stable/c/4bc5f1f6bc94e695dfd912122af96e7115a0ddb8 - () https://git.kernel.org/stable/c/4bc5f1f6bc94e695dfd912122af96e7115a0ddb8 - Patch
References () https://git.kernel.org/stable/c/7879626296e6ffd838ae0f2af1ab49ee46354973 - () https://git.kernel.org/stable/c/7879626296e6ffd838ae0f2af1ab49ee46354973 - Patch
References () https://git.kernel.org/stable/c/867dbe784c5010a466f00a7d1467c1c5ea569c75 - () https://git.kernel.org/stable/c/867dbe784c5010a466f00a7d1467c1c5ea569c75 - Patch
References () https://git.kernel.org/stable/c/8a7b9560a3a8eb8724888c426e05926752f73aa0 - () https://git.kernel.org/stable/c/8a7b9560a3a8eb8724888c426e05926752f73aa0 - Patch
References () https://git.kernel.org/stable/c/ad67de330d83e8078372b52af18ffe8d39e26c85 - () https://git.kernel.org/stable/c/ad67de330d83e8078372b52af18ffe8d39e26c85 - Patch
References () https://git.kernel.org/stable/c/c431a3d642593bbdb99e8a9e3eed608b730db6f8 - () https://git.kernel.org/stable/c/c431a3d642593bbdb99e8a9e3eed608b730db6f8 - Patch
CPE cpe:2.3:o:linux:linux_kernel:6.2:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.2:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.2:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.2:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

27 Mar 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-27 17:15

Updated : 2025-10-30 16:20


NVD link : CVE-2023-53019

Mitre link : CVE-2023-53019

CVE.ORG link : CVE-2023-53019


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-129

Improper Validation of Array Index