vdpa: Add max vqp attr to vdpa_nl_policy for nlattr length check
Summary
| CVE | CVE-2023-53543 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-10-04 16:15:49 UTC |
| Updated | 2026-06-18 14:29:50 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: vdpa: Add max vqp attr to vdpa_nl_policy for nlattr length check The vdpa_nl_policy structure is used to validate the nlattr when parsing the incoming nlmsg. It will ensure the attribute being described produces a valid nlattr pointer in info->attrs before entering into each handler in vdpa_nl_ops. That is to say, the missing part in vdpa_nl_policy may lead to illegal nlattr after parsing, which could lead to OOB read just like CVE-2023-3773. This patch adds the missing nla_policy for vdpa max vqp attr to avoid such bugs. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-787
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 447092100c7e71aa20469a270fcee441d807ed58 baed19c108ac8287425b93a44985bbe9a0b1af8d git | Not specified |
| CNA | Linux | Linux | affected ad69dd0bf26b88ec6ab26f8bbe5cd74fbed7672a ff71709445ac033e6e250d971683110e4781c068 git | Not specified |
| CNA | Linux | Linux | affected ad69dd0bf26b88ec6ab26f8bbe5cd74fbed7672a ea65e8b5e6b1a34deda7564f09c90e9e80db436a git | Not specified |
| CNA | Linux | Linux | affected ad69dd0bf26b88ec6ab26f8bbe5cd74fbed7672a 5d6ba607d6cb5c58a4ddf33381e18c83dbb4098f git | Not specified |
| CNA | Linux | Linux | affected 5.15.198 5.15.209 semver | Not specified |
| CNA | Linux | Linux | affected 5.16 | Not specified |
| CNA | Linux | Linux | unaffected 5.16 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.209 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.47 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.4.12 6.4.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.5 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/baed19c108ac8287425b93a44985bbe9a0b1af8d | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/5d6ba607d6cb5c58a4ddf33381e18c83dbb4098f | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/ff71709445ac033e6e250d971683110e4781c068 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/ea65e8b5e6b1a34deda7564f09c90e9e80db436a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.