CVE-2023-52669

HIGH

Linux Kernel 3.0-5.10.210 - Out-of-bounds Write in AES CTR Mode

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: s390/aes - Fix buffer overread in CTR mode When processing the last block, the s390 ctr code will always read a whole block, even if there isn't a whole block of data left. Fix this by using the actual length left and copy it into a buffer first for processing.

Scores

CVSS v3 7.8
EPSS 0.0002
EPSS Percentile 3.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (16)
debian/debian_linux 10.0
Linux/Linux < 3.0
Linux/Linux 0200f3ecc19660bebeabbcbaf212957fcf1dbf8f - a7f580cdb42ec3d53bbb7c4e4335a98423703285
Linux/Linux 0200f3ecc19660bebeabbcbaf212957fcf1dbf8f - cd51e26a3b89706beec64f2d8296cfb1c34e0c79
Linux/Linux 0200f3ecc19660bebeabbcbaf212957fcf1dbf8f - d07f951903fa9922c375b8ab1ce81b18a0034e3b
Linux/Linux 0200f3ecc19660bebeabbcbaf212957fcf1dbf8f - d68ac38895e84446848b7647ab9458d54cacba3e
Linux/Linux 0200f3ecc19660bebeabbcbaf212957fcf1dbf8f - dbc9a791a70ea47be9f2acf251700fe254a2ab23
Linux/Linux 0200f3ecc19660bebeabbcbaf212957fcf1dbf8f - e78f1a43e72daf77705ad5b9946de66fc708b874
Linux/Linux 3.0
Linux/Linux 5.10.210 - 5.10.*
... and 6 more
Published May 17, 2024
Tracked Since Feb 18, 2026