Out-of-bounds read in Linux kernel - CVE-2023-52626

 

Out-of-bounds read in Linux kernel - CVE-2023-52626

Published: June 8, 2024 / Updated: May 13, 2025


Vulnerability identifier: #VU91401
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-52626
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds read error within the mlx5e_ptp_handle_ts_cqe() function in drivers/net/ethernet/mellanox/mlx5/core/en/ptp.c. A local user can perform a denial of service (DoS) attack.


Affected software

Linux kernel
Oracle Linux
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for x86_64
Ubuntu
IBM Integrated Analytics System
IBM QRadar Network Packet Capture
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Technical Support Appliance
Red Hat OpenShift Dev Spaces
OpenShift Logging
IBM Cloud Pak for Business Automation
IBM Business Automation Workflow
Red Hat OpenShift Container Platform
kernel (Red Hat package)
kernel-rt (Red Hat package)
kernel-tools-libs
bpftool
kernel
kernel-doc
kernel-abi-stablelists
python3-perf
perf
kernel-core
kernel-cross-headers
kernel-debug
kernel-debug-core
kernel-debug-devel
kernel-debug-modules
kernel-debug-modules-extra
kernel-devel
kernel-headers
kernel-modules
kernel-modules-extra
kernel-tools
kernel-tools-libs-devel
linux-image-virtual-hwe-22.04 (Ubuntu package)
linux-image-generic-hwe-22.04 (Ubuntu package)
linux-image-generic-64k-hwe-22.04 (Ubuntu package)
linux-image-6.5.0-41-generic-64k (Ubuntu package)
linux-image-6.5.0-41-generic (Ubuntu package)
linux-image-6.5.0-1017-laptop (Ubuntu package)
linux-image-laptop-23.10 (Ubuntu package)
linux-image-6.5.0-1021-nvidia (Ubuntu package)
linux-image-6.5.0-1021-nvidia-64k (Ubuntu package)
linux-image-nvidia-6.5 (Ubuntu package)
linux-image-nvidia-64k-6.5 (Ubuntu package)
linux-image-nvidia-hwe-22.04 (Ubuntu package)
linux-image-nvidia-64k-hwe-22.04 (Ubuntu package)
linux-image-6.5.0-1022-oem (Ubuntu package)
linux-image-oem-22.04d (Ubuntu package)
linux-image-oem-22.04c (Ubuntu package)
linux-image-oem-22.04b (Ubuntu package)
linux-image-oem-22.04a (Ubuntu package)
linux-image-oem-22.04 (Ubuntu package)
IBM Security Guardium

How to mitigate CVE-2023-52626

Install update from vendor's website.

Linux kernel - addressed in versions 6.6.15, 6.7.3, 6.8
IBM Integrated Analytics System - update to 1.0.31.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF02
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
Technical Support Appliance - update to 3.0.1
Red Hat OpenShift Dev Spaces - update to 3.15.0
Red Hat OpenShift Container Platform - addressed in versions 4.13.45, 4.14.32, 4.14.33, 4.15.21, 4.16.1
kernel (Red Hat package) - addressed in versions 4.18.0-553.8.1.el8_10, 5.14.0-427.24.1.el9_4
kernel-rt (Red Hat package) - update to 4.18.0-553.8.1.rt7.349.el8_10
kernel-tools-libs - update to 4.18.0-553.8.1.0.1
bpftool - update to 4.18.0-553.8.1.0.1
kernel - update to 4.18.0-553.8.1.0.1
kernel-doc - update to 4.18.0-553.8.1.0.1
kernel-abi-stablelists - update to 4.18.0-553.8.1.0.1
python3-perf - update to 4.18.0-553.8.1.0.1
perf - update to 4.18.0-553.8.1.0.1
kernel-core - update to 4.18.0-553.8.1.0.1
kernel-cross-headers - update to 4.18.0-553.8.1.0.1
kernel-debug - update to 4.18.0-553.8.1.0.1
kernel-debug-core - update to 4.18.0-553.8.1.0.1
kernel-debug-devel - update to 4.18.0-553.8.1.0.1
kernel-debug-modules - update to 4.18.0-553.8.1.0.1
kernel-debug-modules-extra - update to 4.18.0-553.8.1.0.1
kernel-devel - update to 4.18.0-553.8.1.0.1
kernel-headers - update to 4.18.0-553.8.1.0.1
kernel-modules - update to 4.18.0-553.8.1.0.1
kernel-modules-extra - update to 4.18.0-553.8.1.0.1
kernel-tools - update to 4.18.0-553.8.1.0.1
kernel-tools-libs-devel - update to 4.18.0-553.8.1.0.1
OpenShift Logging - update to 5.6.21
linux-image-virtual-hwe-22.04 (Ubuntu package) - update to 6.5.0.41.41~22.04.2
linux-image-generic-hwe-22.04 (Ubuntu package) - update to 6.5.0.41.41~22.04.2
linux-image-generic-64k-hwe-22.04 (Ubuntu package) - update to 6.5.0.41.41~22.04.2
linux-image-6.5.0-41-generic-64k (Ubuntu package) - update to 6.5.0-41.41~22.04.2
linux-image-6.5.0-41-generic (Ubuntu package) - update to 6.5.0-41.41~22.04.2
linux-image-6.5.0-1017-laptop (Ubuntu package) - update to 6.5.0-1017.20
linux-image-laptop-23.10 (Ubuntu package) - update to 6.5.0.1017.20
linux-image-6.5.0-1021-nvidia (Ubuntu package) - update to 6.5.0-1021.22
linux-image-6.5.0-1021-nvidia-64k (Ubuntu package) - update to 6.5.0-1021.22
linux-image-nvidia-6.5 (Ubuntu package) - update to 6.5.0.1021.29
linux-image-nvidia-64k-6.5 (Ubuntu package) - update to 6.5.0.1021.29
linux-image-nvidia-hwe-22.04 (Ubuntu package) - update to 6.5.0.1021.29
linux-image-nvidia-64k-hwe-22.04 (Ubuntu package) - update to 6.5.0.1021.29
linux-image-6.5.0-1022-oem (Ubuntu package) - update to 6.5.0-1022.23
linux-image-oem-22.04d (Ubuntu package) - update to 6.5.0.1022.24
linux-image-oem-22.04c (Ubuntu package) - update to 6.5.0.1022.24
linux-image-oem-22.04b (Ubuntu package) - update to 6.5.0.1022.24
linux-image-oem-22.04a (Ubuntu package) - update to 6.5.0.1022.24
linux-image-oem-22.04 (Ubuntu package) - update to 6.5.0.1022.24
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 10
IBM Security Guardium - update to 12.0p26
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF035, 24.0.0-IF001
IBM Business Automation Workflow - update to 24.0.0-IF002

External References

Related Security Bulletins