CVE-2023-53722

UnknownEPSS 0.19%

Last modified

CVE-2023-53722 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: md: raid1: fix potential OOB in raid1_remove_disk() If rddev->raid_disk is greater than mddev->raid_disks, there will be an out-of-bounds in raid1_remove_disk(). We have already found similar reports as follows: 1) commit d17f744e883b ("md-raid10: fix KASAN warning") 2) commit 1ebc2cec0b7d ("dm raid: fix KASAN warning in raid5_remove_disk") Fix this bug by checking whether the "number" variable is valid.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: md: raid1: fix potential OOB in raid1_remove_disk() If rddev->raid_disk is greater than mddev->raid_disks, there will be an out-of-bounds in raid1_remove_disk(). We have already found similar reports as follows: 1) commit d17f744e883b ("md-raid10: fix KASAN warning") 2) commit 1ebc2cec0b7d ("dm raid: fix KASAN warning in raid5_remove_disk") Fix this bug by checking whether the "number" variable is valid.

Metrics

EPSS Probability
0.19%

9.1th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= b8321b68d1445f308324517e45fb0a5c2b48e271, < beedf40f73939f248c81802eda08a2a8148ea13e; >= b8321b68d1445f308324517e45fb0a5c2b48e271, < 91fbd4e75cb573f44d2619a9dc2f9ba927040760; >= b8321b68d1445f308324517e45fb0a5c2b48e271, < 25a68f2286be56fb3a6f9fa0e269c04b5e6c6e24; >= b8321b68d1445f308324517e45fb0a5c2b48e271, < 7993cfc041481a3a9cd4a3858088fc846b8ccaf7; >= b8321b68d1445f308324517e45fb0a5c2b48e271, < 4f96c0665f9f4cf70130c9757750dc43dc679c82; >= b8321b68d1445f308324517e45fb0a5c2b48e271, < 4f7d853b4590fc20e90dd50e346c02811a8c5b08; >= b8321b68d1445f308324517e45fb0a5c2b48e271, < 4bdb92eaf645e312975357adc3c4e9523b6e67f1; >= b8321b68d1445f308324517e45fb0a5c2b48e271, < 8b0472b50bcf0f19a5119b00a53b63579c8e1e4d
LinuxLinux3.3

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2023-53722?
In the Linux kernel, the following vulnerability has been resolved: md: raid1: fix potential OOB in raid1_remove_disk() If rddev->raid_disk is greater than mddev->raid_disks, there will be an out-of-bounds in raid1_remove_disk(). We have already found similar reports as follows: 1) commit d17f744e883b ("md-raid10: fix KASAN warning") 2) commit 1ebc2cec0b7d ("dm raid: fix KASAN warning in raid5_remove_disk") Fix this bug by checking whether the "number" variable is valid.
How severe is CVE-2023-53722?
Severity scoring for CVE-2023-53722 is pending analysis. The EPSS model estimates a 0.19% probability of exploitation in the next 30 days.
How do I fix CVE-2023-53722?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2023

Are you affected by CVE-2023-53722?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST