CVE-2023-52916

HIGH

Linux Kernel 5.0-6.1.119 - Out-of-bounds Write in ASPEED Media Capture

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: media: aspeed: Fix memory overwrite if timing is 1600x900 When capturing 1600x900, system could crash when system memory usage is tight. The way to reproduce this issue: 1. Use 1600x900 to display on host 2. Mount ISO through 'Virtual media' on OpenBMC's web 3. Run script as below on host to do sha continuously #!/bin/bash while [ [1] ]; do find /media -type f -printf '"%h/%f"\n' | xargs sha256sum done 4. Open KVM on OpenBMC's web The size of macro block captured is 8x8. Therefore, we should make sure the height of src-buf is 8 aligned to fix this issue.

Scores

CVSS v3 7.8
EPSS 0.0022
EPSS Percentile 12.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (7)
Linux/Linux < 5.0
Linux/Linux 5.0
Linux/Linux 6.1.120 - 6.1.*
Linux/Linux 6.6
Linux/Linux d2b4387f3bdf016e266d23cf657465f557721488 - 4c823e4027dd1d6e88c31028dec13dd19bc7b02d
Linux/Linux d2b4387f3bdf016e266d23cf657465f557721488 - c281355068bc258fd619c5aefd978595bede7bfe
linux/linux_kernel 5.0 - 6.1.120
Published Sep 06, 2024
Tracked Since Feb 18, 2026