CVE-2023-53400

MEDIUM

Linux Kernel < 4.14.316 - Denial of Service via ALSA HDA 9.1 Surround Channel Name Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: Fix Oops by 9.1 surround channel names get_line_out_pfx() may trigger an Oops by overflowing the static array with more than 8 channels. This was reported for MacBookPro 12,1 with Cirrus codec. As a workaround, extend for the 9.1 channels and also fix the potential Oops by unifying the code paths accessing the same array with the proper size check.

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 3.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (27)
linux/Kernel 3.9.0 - 4.14.316linux
linux/Kernel 4.15.0 - 4.19.284linux
linux/Kernel 4.20.0 - 5.4.244linux
linux/Kernel 5.11.0 - 5.15.113linux
linux/Kernel 5.16.0 - 6.1.30linux
linux/Kernel 5.5.0 - 5.10.181linux
linux/Kernel 6.2.0 - 6.3.4linux
Linux/Linux < 3.9
Linux/Linux 247d85ee068610c50d66ee0cd3130e02c69f5f2e - 082dcd51667b29097500c824c37f24da997a6a8a
Linux/Linux 247d85ee068610c50d66ee0cd3130e02c69f5f2e - 3b44ec8c5c44790a82f07e90db45643c762878c6
... and 17 more
Published Sep 18, 2025
Tracked Since Feb 18, 2026