Wind River Support Network

HomeDefectsLIN1019-11564
Fixed

LIN1019-11564 : Security Advisory - linux - CVE-2023-52626

Created: Mar 26, 2024    Updated: May 31, 2024
Resolved Date: May 31, 2024
Found In Version: 10.19.45.1
Fix Version: 10.19.45.30
Severity: Standard
Applicable for: Wind River Linux LTS 19
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5e: Fix operation precedence bug in port timestamping napi_poll context

Indirection (*) is of lower precedence than postfix increment (++). Logic
in napi_poll context would cause an out-of-bound read by first increment
the pointer address by byte address space and then dereference the value.
Rather, the intended logic was to dereference first and then increment the
underlying value.

CREATE(Triage):(User=admin) CVE-2023-52626 (https://nvd.nist.gov/vuln/detail/CVE-2023-52626)

CVEs


Live chat
Online