CVE-2023-54031 is a vulnerability in the Linux kernel's vdpa subsystem, specifically related to the vdpa_nl_policy structure. A missing policy for the vdpa queue index attribute could lead to out-of-bounds (OOB) read vulnerabilities, similar to CVE-2023-3773. The attack vector involves malformed netlink messages, but the complexity and specific impact are not detailed. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 5.19CNA affecteddefault affected | |
| Linux | Linux | >= 13b00b135665c92065a27c0c39dd97e0f380bd4f, < 8ad9bc25cbdcec72e7ca43dd8281decb69ea9a70, >= 13b00b135665c92065a27c0c39dd97e0f380bd4f, < b3003e1b54e057f5f3124e437b80c3bef26ed3fe, >= 13b00b135665c92065a27c0c39dd97e0f380bd4f, < ccb533b7070aeeb65c66ea5d590e9c62421dcd61CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.