CVE-2023-53331 is a high-severity vulnerability in the Linux kernel's pstore/ram component. It stems from insufficient validation during initialization of persistent RAM buffers, where an unchecked zero buffer_size could lead to an out-of-bounds memory access if the buffer start position is invalid. This flaw can result in a kernel panic, causing a denial of service and potentially impacting confidentiality and integrity. The vulnerability has a CVSS score of 7.8 (High) due to its local attack vector, low complexity, and high impact on availability, confidentiality, and integrity. There is currently no public exploit code, Metasploit modules, or Nuclei templates available, and it has not been observed in active exploitation or received significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.18.133, < 3.19CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.9.153, < 4.10CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.14.96, < 4.14.326CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.19.18, < 4.19.295CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.20.5, < 4.21CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.