CVE-2023-53034
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans There is a kernel API ntb_mw_clear_trans() would pass 0 to both addr and size. This would make xlate_pos negative. [ 23.734156] switchtec switchtec0: MW 0: part 0 addr 0x0000000000000000 size 0x0000000000000000 [ 23.734158] ================================================================================ [ 23.734172] UBSAN: shift-out-of-bounds in drivers/ntb/hw/mscc/ntb_hw_switchtec.c:293:7 [ 23.734418] shift exponent -1 is negative Ensuring xlate_pos is a positive or zero before BIT.
CVSS Metrics
- v3.1•HIGH•Score: 7.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
- v3.1•HIGH•Score: 7.1CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
EPSS Trends
Current EPSS score: 0.29%• Percentile: 22%
Techniques & Countermeasures
- CWE-125•Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
Affected Systems
- debian•linux
< 5.10.237-1 | < 6.1.135-1 | < 6.12.25-1 | < 6.12.25-1
- debian•linux-6.1
< 6.1.137-1~deb11u1
- ubuntu•linux
< 5.4.0-218.238 | < 5.15.0-142.152 | < 6.8.0-86.87
- ubuntu•linux-allwinner-5.19
all
- ubuntu•linux-aws
< 5.4.0-1147.157 | < 5.15.0-1086.93 | < 6.8.0-1041.43
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
all
- ubuntu•linux-aws-5.15
< 5.15.0-1086.93~20.04.1
- ubuntu•linux-aws-5.19
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.4
< 5.4.0-1147.157~18.04.1
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-6.2
all
- ubuntu•linux-aws-6.5
all
- ubuntu•linux-aws-6.8
< 6.8.0-1041.43~22.04.1
- ubuntu•linux-aws-fips
< 5.4.0-1147.157+fips1 | all | < 5.15.0-1086.93+fips1 | < 6.8.0-1041.43+fips1
- ubuntu•linux-azure
all | < 5.4.0-1152.159 | < 5.15.0-1091.100 | < 6.8.0-1041.47
- ubuntu•linux-azure-5.11
all
- ubuntu•linux-azure-5.13
all
- ubuntu•linux-azure-5.15
< 5.15.0-1091.100~20.04.1
- ubuntu•linux-azure-5.19
all
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.4
< 5.4.0-1152.159~18.04.1
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-6.11
< 6.11.0-1018.18~24.04.1
- ubuntu•linux-azure-6.2
all
- ubuntu•linux-azure-6.5
all
- ubuntu•linux-azure-6.8
< 6.8.0-1041.47~22.04.1
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde
all | all | all
- ubuntu•linux-azure-fde-5.19
all
- ubuntu•linux-azure-fde-6.2
all
- ubuntu•linux-azure-fips
< 5.4.0-1153.160+fips1 | all | < 5.15.0-1091.100+fips1 | < 6.8.0-1044.50+fips1
- ubuntu•linux-azure-nvidia
< 6.8.0-1029.32
- ubuntu•linux-bluefield
all | < 5.4.0-1106.113 | < 5.15.0-1069.71 | < 6.8.0-1012.16
- ubuntu•linux-fips
< 5.4.0-1121.131 | all | < 5.15.0-142.152+fips1 | < 6.8.0-86.87+fips1
- ubuntu•linux-gcp
all | < 5.4.0-1150.159 | < 5.15.0-1085.94 | < 6.8.0-1042.45
- ubuntu•linux-gcp-5.11
all
- ubuntu•linux-gcp-5.13
all
- ubuntu•linux-gcp-5.15
< 5.15.0-1085.94~20.04.1
- ubuntu•linux-gcp-5.19
all
- ubuntu•linux-gcp-5.3
all
- ubuntu•linux-gcp-5.4
< 5.4.0-1150.159~18.04.1
- ubuntu•linux-gcp-5.8
all
- ubuntu•linux-gcp-6.11
< 6.11.0-1016.16~24.04.1
- ubuntu•linux-gcp-6.2
all
- ubuntu•linux-gcp-6.5
all
- ubuntu•linux-gcp-6.8
< 6.8.0-1042.45~22.04.1
- ubuntu•linux-gcp-fips
< 5.4.0-1150.159+fips1 | all | < 5.15.0-1085.94+fips1 | < 6.8.0-1042.45+fips1
Showing first 50 affected entries in server-rendered view.
References (53)
- https://git.kernel.org/stable/c/f56951f211f181410a383d305e8d370993e45294
- https://git.kernel.org/stable/c/5b6857bb3bfb0dae17fab1e42c1e82c204a508b1
- https://git.kernel.org/stable/c/2429bdf26a0f3950fdd996861e9c1a3873af1dbe
- https://git.kernel.org/stable/c/7ed22f8d8be26225a78cf5e85b2036421a6bf2d5
- https://git.kernel.org/stable/c/c61a3f2df162ba424be0141649a9ef5f28eaccc1
- https://git.kernel.org/stable/c/cb153bdc1812a3375639ed6ca5f147eaefb65349
- https://git.kernel.org/stable/c/36d32cfb00d42e865396424bb5d340fc0a28870d
- https://git.kernel.org/stable/c/0df2e03e4620548b41891b4e0d1bd9d2e0d8a39a
- https://git.kernel.org/stable/c/de203da734fae00e75be50220ba5391e7beecdf9
- https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html
- https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html
- https://ubuntu.com/security/CVE-2023-53034
- https://www.cve.org/CVERecord?id=CVE-2023-53034
- https://git.kernel.org/linus/de203da734fae00e75be50220ba5391e7beecdf9
- https://ubuntu.com/security/notices/USN-7585-1
- https://ubuntu.com/security/notices/USN-7585-2
- https://ubuntu.com/security/notices/USN-7591-1
- https://ubuntu.com/security/notices/USN-7591-2
- https://ubuntu.com/security/notices/USN-7591-3
- https://ubuntu.com/security/notices/USN-7592-1
- https://ubuntu.com/security/notices/USN-7593-1
- https://ubuntu.com/security/notices/USN-7594-1
- https://ubuntu.com/security/notices/USN-7591-4
- https://ubuntu.com/security/notices/USN-7597-1
- https://ubuntu.com/security/notices/USN-7597-2
- https://ubuntu.com/security/notices/USN-7598-1
- https://ubuntu.com/security/notices/USN-7585-3
- https://ubuntu.com/security/notices/USN-7585-4
- https://ubuntu.com/security/notices/USN-7594-2
- https://ubuntu.com/security/notices/USN-7602-1
- https://ubuntu.com/security/notices/USN-7585-5
- https://ubuntu.com/security/notices/USN-7605-1
- https://ubuntu.com/security/notices/USN-7606-1
- https://ubuntu.com/security/notices/USN-7585-6
- https://ubuntu.com/security/notices/USN-7591-5
- https://ubuntu.com/security/notices/USN-7605-2
- https://ubuntu.com/security/notices/USN-7594-3
- https://ubuntu.com/security/notices/USN-7628-1
- https://ubuntu.com/security/notices/USN-7585-7
- https://ubuntu.com/security/notices/USN-7640-1
- https://ubuntu.com/security/notices/USN-7591-6
- https://ubuntu.com/security/notices/USN-7655-1
- https://ubuntu.com/security/notices/USN-7835-1
- https://ubuntu.com/security/notices/USN-7835-2
- https://ubuntu.com/security/notices/USN-7835-3
- https://ubuntu.com/security/notices/USN-7835-4
- https://ubuntu.com/security/notices/USN-7835-5
- https://ubuntu.com/security/notices/USN-7835-6
- https://ubuntu.com/security/notices/USN-7887-1
- https://ubuntu.com/security/notices/USN-7887-2
- https://ubuntu.com/security/notices/USN-7940-1
- https://ubuntu.com/security/notices/USN-7940-2
- https://security-tracker.debian.org/tracker/CVE-2023-53034