CVE-2023-54245
Last modified
CVE-2023-54245 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: tx-macro: Fix for KASAN: slab-out-of-bounds When we run syzkaller we get below Out of Bound. "KASAN: slab-out-of-bounds Read in regcache_flat_read" Below is the backtrace of the issue: dump_backtrace+0x0/0x4c8 show_stack+0x34/0x44 dump_stack_lvl+0xd8/0x118 print_address_description+0x30/0x2d8 kasan_report+0x158/0x198 __asan_report_load4_noabort+0x44/0x50 regcache_flat_read+0x10c/0x110 regcache_read+0xf4/0x180 _regmap_read+0xc4/0x278 _regmap_update_bits+0x130/0x290 regmap_update_bits_base+0xc0/0x15c snd_soc_component_update_bits+0xa8/0x22c snd_soc_component_write_field+0x68/0xd4 tx_macro_digital_mute+0xec/0x140 Actually There is no need to have decimator with 32 bits. By limiting the variable with short type u8 issue is resolved.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: tx-macro: Fix for KASAN: slab-out-of-bounds When we run syzkaller we get below Out of Bound. "KASAN: slab-out-of-bounds Read in regcache_flat_read" Below is the backtrace of the issue: dump_backtrace+0x0/0x4c8 show_stack+0x34/0x44 dump_stack_lvl+0xd8/0x118 print_address_description+0x30/0x2d8 kasan_report+0x158/0x198 __asan_report_load4_noabort+0x44/0x50 regcache_flat_read+0x10c/0x110 regcache_read+0xf4/0x180 _regmap_read+0xc4/0x278 _regmap_update_bits+0x130/0x290 regmap_update_bits_base+0xc0/0x15c snd_soc_component_update_bits+0xa8/0x22c snd_soc_component_write_field+0x68/0xd4 tx_macro_digital_mute+0xec/0x140 Actually There is no need to have decimator with 32 bits. By limiting the variable with short type u8 issue is resolved.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= d207bdea0ca9efde321ff142e9b9f2ef73f9cdf5, < da35a4e6eee5d73886312e85322a6e97df901987; >= d207bdea0ca9efde321ff142e9b9f2ef73f9cdf5, < 57f9a9a232bde7abfe49c3072b29a255da9ba891; >= d207bdea0ca9efde321ff142e9b9f2ef73f9cdf5, < b0cd740a31412340fead50e69e4fe9bc3781c754; >= d207bdea0ca9efde321ff142e9b9f2ef73f9cdf5, < e5e7e398f6bb7918dab0612eb6991f7bae95520d |
| Linux | Linux | 5.12 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2023-54245?
How severe is CVE-2023-54245?
How do I fix CVE-2023-54245?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-5424The WS Form LITE plugin for WordPress is vulnerable to CSV I…8.8
- CVE-2023-54240In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54241In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54242In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54243In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-54244In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54246In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54247In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54248In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54249In the Linux kernel, the following vulnerability has been re…
- CVE-2023-5425The Post Meta Data Manager plugin for WordPress is vulnerabl…8.8
- CVE-2023-54250In the Linux kernel, the following vulnerability has been re…8.2
Are you affected by CVE-2023-54245?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
