Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-52454— nvmet-tcp: Fix a kernel panic when host sends an invalid H2C PDU length

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux Kernel 存在安全漏洞,该漏洞源于主机发送无效 H2C PDU 长度时出现内核恐慌。

CVSS 7.5 · High EPSS 0.68% · P51

Possible ATT&CK Techniques 1 AI

T1211 · Exploitation for Stealth

Affected Version Matrix 16

VendorProduct Version RangeStatus
Linux Linux 872d26a391da92ed8f0c0f5cb5fef428067b7f30< ee5e7632e981673f42a50ade25e71e612e543d9d affected
872d26a391da92ed8f0c0f5cb5fef428067b7f30< f775f2621c2ac5cc3a0b3a64665dad4fb146e510 affected
872d26a391da92ed8f0c0f5cb5fef428067b7f30< 4cb3cf7177ae3666be7fb27d4ad4d72a295fb02d affected
872d26a391da92ed8f0c0f5cb5fef428067b7f30< 2871aa407007f6f531fae181ad252486e022df42 affected
872d26a391da92ed8f0c0f5cb5fef428067b7f30< 24e05760186dc070d3db190ca61efdbce23afc88 affected
872d26a391da92ed8f0c0f5cb5fef428067b7f30< 70154e8d015c9b4fb56c1a2ef1fc8b83d45c7f68 affected
872d26a391da92ed8f0c0f5cb5fef428067b7f30< efa56305908ba20de2104f1b8508c6a7401833be affected
5.0 affected
… +8 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-52454

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
nvmet-tcp: Fix a kernel panic when host sends an invalid H2C PDU length
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix a kernel panic when host sends an invalid H2C PDU length If the host sends an H2CData command with an invalid DATAL, the kernel may crash in nvmet_tcp_build_pdu_iovec(). Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 lr : nvmet_tcp_io_work+0x6ac/0x718 [nvmet_tcp] Call trace: process_one_work+0x174/0x3c8 worker_thread+0x2d0/0x3e8 kthread+0x104/0x110 Fix the bug by raising a fatal error if DATAL isn't coherent with the packet size. Also, the PDU length should never exceed the MAXH2CDATA parameter which has been communicated to the host in nvmet_tcp_handle_icreq().
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux Kernel 存在安全漏洞,该漏洞源于主机发送无效 H2C PDU 长度时出现内核恐慌。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 872d26a391da92ed8f0c0f5cb5fef428067b7f30 ~ ee5e7632e981673f42a50ade25e71e612e543d9d -
Linux Linux 5.0 -

II. Public POCs for CVE-2023-52454

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-52454

请登录查看更多情报信息。

Mailing List Discussions for CVE-2023-52454 (1)

Other References for CVE-2023-52454 (6)

Same Patch Batch · Linux · 2024-02-23 · 19 CVEs total

CVE-2024-26594 9.1 CRITICAL ksmbd: validate mech token in session setup
CVE-2024-26598 8.8 HIGH KVM: arm64: vgic-its: Avoid potential UAF in LPI translation cache
CVE-2024-26597 7.8 HIGH net: qualcomm: rmnet: fix global oob in rmnet_policy
CVE-2023-52461 7.8 HIGH drm/sched: Fix bounds limiting when given a malformed entity
CVE-2023-52453 7.1 HIGH hisi_acc_vfio_pci: Update migration data pointer correctly on saving/resume
CVE-2024-26593 i2c: i801: Fix block process call transactions
CVE-2023-52455 iommu: Don't reserve 0-length IOVA region
CVE-2023-52456 serial: imx: fix tx statemachine deadlock
CVE-2023-52458 block: add check that partition length needs to be aligned with block size
CVE-2023-52457 serial: 8250: omap: Don't skip resource freeing if pm_runtime_resume_and_get() failed
CVE-2023-52459 media: v4l: async: Fix duplicated list deletion
CVE-2023-52460 drm/amd/display: Fix NULL pointer dereference at hibernate
CVE-2023-52462 bpf: fix check for attempt to corrupt spilled pointer
CVE-2023-52464 EDAC/thunderx: Fix possible out-of-bounds string access
CVE-2023-52463 efivarfs: force RO when remounting if SetVariable is not supported
CVE-2024-26596 net: dsa: fix netdev_priv() dereference before check on non-DSA netdevice events
CVE-2024-26595 mlxsw: spectrum_acl_tcam: Fix NULL pointer dereference in error path
CVE-2024-26599 pwm: Fix out-of-bounds access in of_pwm_single_xlate()

IV. Related Vulnerabilities

V. Comments for CVE-2023-52454

No comments yet


Leave a comment