CVE-2023-53661

MEDIUM

Linux Kernel - Integer Overflow in bnxt_get_nvram_directory()

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: bnxt: avoid overflow in bnxt_get_nvram_directory() The value of an arithmetic expression is subject of possible overflow due to a failure to cast operands to a larger data type before performing arithmetic. Used macro for multiplication instead operator for avoiding overflow. Found by Security Code and Linux Verification Center (linuxtesting.org) with SVACE.

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 3.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-190
Status published
Products (11)
Linux/Linux < 4.4
Linux/Linux 4.4
Linux/Linux 5.15.113 - 5.15.*
Linux/Linux 6.1.30 - 6.1.*
Linux/Linux 6.3.4 - 6.3.*
Linux/Linux 6.4
Linux/Linux c0c050c58d840994ba842ad1c338a98e7c12b764 - 17e0453a7523ad7a25bb47af941b150a6c66d7b6
Linux/Linux c0c050c58d840994ba842ad1c338a98e7c12b764 - 7c6dddc239abe660598c49ec95ea0ed6399a4b2a
Linux/Linux c0c050c58d840994ba842ad1c338a98e7c12b764 - d5eaf2a6b077f32a477feb1e9e1c1f60605b460e
Linux/Linux c0c050c58d840994ba842ad1c338a98e7c12b764 - efb1a257513438d43f4335f09b2f684e8167cad2
... and 1 more
Published Oct 07, 2025
Tracked Since Feb 18, 2026