CVE Database
/

CVE-2023-52618

Back to search

CVE-2023-52618

Published: Mar 18, 2024

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: block/rnbd-srv: Check for unlikely string overflow Since "dev_search_path" can technically be as large as PATH_MAX, there was a risk of truncation when copying it and a second string into "full_path" since it was also PATH_MAX sized. The W=1 builds were reporting this warning: drivers/block/rnbd/rnbd-srv.c: In function 'process_msg_open.isra': drivers/block/rnbd/rnbd-srv.c:616:51: warning: '%s' directive output may be truncated writing up to 254 bytes into a region of size between 0 and 4095 [-Wformat-truncation=] 616 | snprintf(full_path, PATH_MAX, "%s/%s", | ^~ In function 'rnbd_srv_get_full_path', inlined from 'process_msg_open.isra' at drivers/block/rnbd/rnbd-srv.c:721:14: drivers/block/rnbd/rnbd-srv.c:616:17: note: 'snprintf' output between 2 and 4351 bytes into a destination of size 4096 616 | snprintf(full_path, PATH_MAX, "%s/%s", | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 617 | dev_search_path, dev_name); | ~~~~~~~~~~~~~~~~~~~~~~~~~~ To fix this, unconditionally check for truncation (as was already done for the case where "%SESSNAME%" was present).

VendorProductVersions

Linux

Linux

affected
2de6c8de192b9341ffa5e84afe1ce6196d4eef41 - < 95bc866c11974d3e4a9d922275ea8127ff809cf7
affected
2de6c8de192b9341ffa5e84afe1ce6196d4eef41 - < f6abd5e17da33eba15df2bddc93413e76c2b55f7
affected
2de6c8de192b9341ffa5e84afe1ce6196d4eef41 - < af7bbdac89739e2e7380387fda598848d3b7010f
affected
2de6c8de192b9341ffa5e84afe1ce6196d4eef41 - < 5b9ea86e662035a886ccb5c76d56793cba618827
affected
2de6c8de192b9341ffa5e84afe1ce6196d4eef41 - < a2c6206f18104fba7f887bf4dbbfe4c41adc4339

+1 more versions

Linux

Linux

affected
5.8
unaffected
0 - < 5.8
unaffected
5.10.210 - <= 5.10.*
unaffected
5.15.149 - <= 5.15.*
unaffected
6.1.77 - <= 6.1.*

+3 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now