CVE-2023-54057

Linux Kernel - Buffer Overflow in parse_ivrs_acpihid via Unbounded sscanf String Specifier

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Add a length limitation for the ivrs_acpihid command-line parameter The 'acpiid' buffer in the parse_ivrs_acpihid function may overflow, because the string specifier in the format string sscanf() has no width limitation. Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with SVACE.

Scores

EPSS 0.0021
EPSS Percentile 11.8%

Details

Status published
Products (19)
linux/Kernel 4.7.0 - 5.4.237linux
linux/Kernel 5.11.0 - 5.15.103linux
linux/Kernel 5.16.0 - 6.1.16linux
linux/Kernel 5.5.0 - 5.10.175linux
linux/Kernel 6.2.0 - 6.2.3linux
Linux/Linux < 4.7
Linux/Linux 4.7
Linux/Linux 5.10.175 - 5.10.*
Linux/Linux 5.15.103 - 5.15.*
Linux/Linux 5.4.237 - 5.4.*
... and 9 more
Published Dec 24, 2025
Tracked Since Feb 18, 2026