UBUNTU-CVE-2023-53034
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-53034
UBUNTU-CVE-2023-53034
Summary:
Details: In the Linux kernel, the following vulnerability has been resolved: ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans There is a kernel API ntb_mw_clear_trans() would pass 0 to both addr and size. This would make xlate_pos negative. [ 23.734156] switchtec switchtec0: MW 0: part 0 addr 0x0000000000000000 size 0x0000000000000000 [ 23.734158] ================================================================================ [ 23.734172] UBSAN: shift-out-of-bounds in drivers/ntb/hw/mscc/ntb_hw_switchtec.c:293:7 [ 23.734418] shift exponent -1 is negative Ensuring xlate_pos is a positive or zero before BIT.
References: https://ubuntu.com/security/CVE-2023-53034, https://www.cve.org/CVERecord?id=CVE-2023-53034, https://git.kernel.org/linus/de203da734fae00e75be50220ba5391e7beecdf9, https://git.kernel.org/stable/c/0df2e03e4620548b41891b4e0d1bd9d2e0d8a39a, https://git.kernel.org/stable/c/2429bdf26a0f3950fdd996861e9c1a3873af1dbe, https://git.kernel.org/stable/c/36d32cfb00d42e865396424bb5d340fc0a28870d, https://git.kernel.org/stable/c/5b6857bb3bfb0dae17fab1e42c1e82c204a508b1, https://git.kernel.org/stable/c/7ed22f8d8be26225a78cf5e85b2036421a6bf2d5, https://git.kernel.org/stable/c/c61a3f2df162ba424be0141649a9ef5f28eaccc1, https://git.kernel.org/stable/c/cb153bdc1812a3375639ed6ca5f147eaefb65349, https://git.kernel.org/stable/c/de203da734fae00e75be50220ba5391e7beecdf9, https://git.kernel.org/stable/c/f56951f211f181410a383d305e8d370993e45294, https://ubuntu.com/security/notices/USN-7585-1, https://ubuntu.com/security/notices/USN-7585-2, https://ubuntu.com/security/notices/USN-7591-1, https://ubuntu.com/security/notices/USN-7591-2, https://ubuntu.com/security/notices/USN-7591-3, https://ubuntu.com/security/notices/USN-7592-1, https://ubuntu.com/security/notices/USN-7593-1, https://ubuntu.com/security/notices/USN-7594-1, https://ubuntu.com/security/notices/USN-7591-4, https://ubuntu.com/security/notices/USN-7597-1, https://ubuntu.com/security/notices/USN-7597-2, https://ubuntu.com/security/notices/USN-7598-1, https://ubuntu.com/security/notices/USN-7585-3, https://ubuntu.com/security/notices/USN-7585-4, https://ubuntu.com/security/notices/USN-7594-2, https://ubuntu.com/security/notices/USN-7602-1, https://ubuntu.com/security/notices/USN-7585-5, https://ubuntu.com/security/notices/USN-7605-1, https://ubuntu.com/security/notices/USN-7606-1, https://ubuntu.com/security/notices/USN-7585-6, https://ubuntu.com/security/notices/USN-7591-5, https://ubuntu.com/security/notices/USN-7605-2, https://ubuntu.com/security/notices/USN-7594-3, https://ubuntu.com/security/notices/USN-7628-1, https://ubuntu.com/security/notices/USN-7585-7, https://ubuntu.com/security/notices/USN-7640-1, https://ubuntu.com/security/notices/USN-7591-6, https://ubuntu.com/security/notices/USN-7655-1, https://ubuntu.com/security/notices/USN-7835-1, https://ubuntu.com/security/notices/USN-7835-2, https://ubuntu.com/security/notices/USN-7835-3, https://ubuntu.com/security/notices/USN-7835-4, https://ubuntu.com/security/notices/USN-7835-5, https://ubuntu.com/security/notices/USN-7835-6, https://ubuntu.com/security/notices/USN-7887-1, https://ubuntu.com/security/notices/USN-7887-2, https://ubuntu.com/security/notices/USN-7940-1, https://ubuntu.com/security/notices/USN-7940-2
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/linux-hwe-edge?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
