Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-53019— net: mdio: validate parameter addr in mdiobus_get_phy()

AI Predicted 5.5 Difficulty: Moderate EPSS 0.19% · P9

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 16

VendorProductVersion RangeStatus
LinuxLinux7f854420fbfe9d49afe2ffb1df052cfe8e215541< 1d80c259dfbadefa61b7ea334dfce5cb57f8c72faffected
7f854420fbfe9d49afe2ffb1df052cfe8e215541< c431a3d642593bbdb99e8a9e3eed608b730db6f8affected
7f854420fbfe9d49afe2ffb1df052cfe8e215541< 8a7b9560a3a8eb8724888c426e05926752f73aa0affected
7f854420fbfe9d49afe2ffb1df052cfe8e215541< 4bc5f1f6bc94e695dfd912122af96e7115a0ddb8affected
7f854420fbfe9d49afe2ffb1df052cfe8e215541< ad67de330d83e8078372b52af18ffe8d39e26c85affected
7f854420fbfe9d49afe2ffb1df052cfe8e215541< 7879626296e6ffd838ae0f2af1ab49ee46354973affected
7f854420fbfe9d49afe2ffb1df052cfe8e215541< 867dbe784c5010a466f00a7d1467c1c5ea569c75affected
4.5affected
… +8 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-53019

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
net: mdio: validate parameter addr in mdiobus_get_phy()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net: mdio: validate parameter addr in mdiobus_get_phy() The caller may pass any value as addr, what may result in an out-of-bounds access to array mdio_map. One existing case is stmmac_init_phy() that may pass -1 as addr. Therefore validate addr before using it.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于mdio未验证phy地址参数。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 7f854420fbfe9d49afe2ffb1df052cfe8e215541 ~ 1d80c259dfbadefa61b7ea334dfce5cb57f8c72f -
LinuxLinux 4.5 -

II. Public POCs for CVE-2023-53019

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-53019

登录查看更多情报信息。

Patches & Fixes for CVE-2023-53019 (1)

Same Patch Batch · Linux · 2025-03-27 · 124 CVEs total

CVE-2023-530069.8 CRITICALcifs: Fix oops due to uncleared server->smbd_conn in reconnect
CVE-2025-218768.8 HIGHiommu/vt-d: Fix suspicious RCU usage
CVE-2025-218908.2 HIGHidpf: fix checksums set in idpf_rx_rsc()
CVE-2023-529837.8 HIGHblock, bfq: fix uaf for bfqq in bic_set_bfqq()
CVE-2023-529307.8 HIGHdrm/i915: Fix potential bit_17 double-free
CVE-2023-529317.8 HIGHdrm/i915: Avoid potential vm use-after-free
CVE-2023-529347.8 HIGHmm/MADV_COLLAPSE: catch !none !huge !bad pmd lookups
CVE-2023-529357.8 HIGHmm/khugepaged: fix ->anon_vma race
CVE-2025-218677.8 HIGHbpf, test_run: Fix use-after-free issue in eth_skb_pkt_type()
CVE-2022-497607.8 HIGHmm/hugetlb: fix PTE marker handling in hugetlb_change_protection()
CVE-2023-529737.8 HIGHvc_screen: move load of struct vc_data pointer in vcs_read() to avoid UAF
CVE-2023-529747.8 HIGHscsi: iscsi_tcp: Fix UAF during login when accessing the shost ipaddress
CVE-2023-529757.8 HIGHscsi: iscsi_tcp: Fix UAF during logout when accessing the shost ipaddress
CVE-2023-530097.8 HIGHdrm/amdkfd: Add sync after creating vram bo
CVE-2023-530337.8 HIGHnetfilter: nft_payload: incorrect arithmetics when fetching VLAN header bits
CVE-2023-530287.8 HIGHRevert "wifi: mac80211: fix memory leak in ieee80211_if_add()"
CVE-2023-530267.8 HIGHRDMA/core: Fix ib block iterator counter overflow
CVE-2023-530237.8 HIGHnet: nfc: Fix use-after-free in local_cleanup()
CVE-2023-530217.8 HIGHnet/sched: sch_taprio: fix possible use-after-free
CVE-2023-529887.8 HIGHALSA: hda/via: Avoid potential array out-of-bound in add_secret_dac_path()

Showing top 20 of 124 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-53019

No comments yet


Leave a comment