We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-52626

net/mlx5e: Fix operation precedence bug in port timestamping napi_poll context



Description

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix operation precedence bug in port timestamping napi_poll context Indirection (*) is of lower precedence than postfix increment (++). Logic in napi_poll context would cause an out-of-bound read by first increment the pointer address by byte address space and then dereference the value. Rather, the intended logic was to dereference first and then increment the underlying value.

Reserved 2024-03-06 | Published 2024-03-26 | Updated 2024-12-19 | Assigner Linux

Product status

Default status
unaffected

e5d30f7da35720060299483e65fc372980a82dfb before 40e0d0746390c5b0c31144f4f1688d72f3f8d790
affected

92214be5979c0961a471b7eaaaeacab41bdf456c before 33cdeae8c6fb58cc445f859b67c014dc9f60b4e0
affected

92214be5979c0961a471b7eaaaeacab41bdf456c before 3876638b2c7ebb2c9d181de1191db0de8cac143a
affected

Default status
affected

6.7
affected

Any version before 6.7
unaffected

6.6.15
unaffected

6.7.3
unaffected

6.8
unaffected

References

git.kernel.org/...c/40e0d0746390c5b0c31144f4f1688d72f3f8d790

git.kernel.org/...c/33cdeae8c6fb58cc445f859b67c014dc9f60b4e0

git.kernel.org/...c/3876638b2c7ebb2c9d181de1191db0de8cac143a

cve.org (CVE-2023-52626)

nvd.nist.gov (CVE-2023-52626)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2023-52626

Support options

Helpdesk Chat, Email, Knowledgebase
Subscribe to our newsletter to learn more about our work.