CVE-2023-53205 is a high-severity vulnerability in the Linux kernel's KVM s390/diag component, specifically affecting the handling of physical CPU numbers during diag 9c operations. This flaw, categorized as an out-of-bounds write (CWE-787), allows a local attacker with low privileges to achieve high confidentiality, integrity, and availability impacts. While the CVSS score is 7.8, there is currently no known public exploit code, Metasploit modules, or Nuclei templates available, and it has not been added to CISA's KEV catalog. Community discussion and media coverage for this CVE are minimal, indicating a low level of public awareness or active exploitation at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.13, < 5.15.121CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.39CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.4.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.