Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-52626
HistoryMar 26, 2024 - 12:00 a.m.

CVE-2023-52626

2024-03-2600:00:00
ubuntu.com
ubuntu.com
10
cve-2023-52626
linux kernel
vulnerability
timestamping
napi_poll

AI Score

6.4

Confidence

High

EPSS

0

Percentile

15.5%

In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Fix operation precedence bug in port timestamping napi_poll
context Indirection (*) is of lower precedence than postfix increment (++).
Logic in napi_poll context would cause an out-of-bound read by first
increment the pointer address by byte address space and then dereference
the value. Rather, the intended logic was to dereference first and then
increment the underlying value.

Notes

Author Note
rodrigo-zaiden USN-6765-1 for linux-oem-6.5 wrongly stated that this CVE was fixed in version 6.5.0-1022.23. The mentioned notice was revoked and the state of the fix for linux-oem-6.5 was recovered to the previous state.
Rows per page:
1-10 of 201