CVE-2023-54104
Last modified
CVE-2023-54104 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: fsl_upm: Fix an off-by one test in fun_exec_op() 'op-cs' is copied in 'fun->mchip_number' which is used to access the 'mchip_offsets' and the 'rnb_gpio' arrays. These arrays have NAND_MAX_CHIPS elements, so the index must be below this limit. Fix the sanity check in order to avoid the NAND_MAX_CHIPS value. This would lead to out-of-bound accesses.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: fsl_upm: Fix an off-by one test in fun_exec_op() 'op-cs' is copied in 'fun->mchip_number' which is used to access the 'mchip_offsets' and the 'rnb_gpio' arrays. These arrays have NAND_MAX_CHIPS elements, so the index must be below this limit. Fix the sanity check in order to avoid the NAND_MAX_CHIPS value. This would lead to out-of-bound accesses.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 54309d65776755bcdb9dcf3744cd764fc1e254ea, < 1f09d67d390647f83f8f9d26382b0daa43756e6f; >= 54309d65776755bcdb9dcf3744cd764fc1e254ea, < eb7a5e4d14c8659cb97db6863316280e15f67209; >= 54309d65776755bcdb9dcf3744cd764fc1e254ea, < f4b700c71802c81e6f9dce362ee7a0312c8377ba; >= 54309d65776755bcdb9dcf3744cd764fc1e254ea, < 49e57caf967a969f6b955c88805f2d160910aa12; >= 54309d65776755bcdb9dcf3744cd764fc1e254ea, < c6abce60338aa2080973cd95be0aedad528bb41f |
| Linux | Linux | 5.9 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2023-54104?
How severe is CVE-2023-54104?
How do I fix CVE-2023-54104?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-54099In the Linux kernel, the following vulnerability has been re…
- CVE-2023-5410A potential security vulnerability has been reported in the …8.2
- CVE-2023-54100In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-54101In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54102In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54103Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2023-54105In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54106In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54107In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-54108In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54109In the Linux kernel, the following vulnerability has been re…
- CVE-2023-5411The Funnelforms Free plugin for WordPress is vulnerable to u…4.3
Are you affected by CVE-2023-54104?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
