CVE-2023-53376 is a memory access vulnerability in the Linux kernel's mpi3mr driver, specifically affecting how bitmap sizes are managed. The driver incorrectly calculates bitmap sizes in bytes, leading to out-of-bounds memory access when using bitmap helper functions that expect sizes in unsigned long units. This flaw, observed during firmware download to eHBA-9600, can result in a kernel crash (KASAN slab-out-of-bounds error). Rated with a CVSS score of 7.1 (HIGH), the vulnerability has a local attack vector and low attack complexity, allowing a low-privileged attacker to achieve high confidentiality and availability impacts. The primary impact is a denial of service due to system instability, with potential for information disclosure. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.14, < 6.1.18CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.2.5CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.