CVE-2023-54065 is an out-of-bounds access vulnerability in the Linux kernel's Realtek network driver, specifically affecting the realtek-mdio component. The flaw arises because the driver incorrectly assumes sufficient trailing memory for chip_data, leading to potential memory corruption. While previously mitigated by an unused buffer, the issue becomes apparent with different memory allocators or KASAN. This vulnerability has no assigned CVSS score, and its FAUCET Risk Score is low at 7/100. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 5.18CNA affecteddefault affected | |
| Linux | Linux | >= aac94001067da183455d6d37959892744fa01d9d, < b93eb564869321d0dffaf23fcc5c88112ed62466, >= aac94001067da183455d6d37959892744fa01d9d, < cc0f9bb99735d2b68fac68f37b585d615728ce5b, >= aac94001067da183455d6d37959892744fa01d9d, < fe668aa499b4b95425044ba11af9609db6ecf466CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.