CVE Database
/

CVE-2023-53019

Back to search

CVE-2023-53019

Published: Mar 27, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: net: mdio: validate parameter addr in mdiobus_get_phy() The caller may pass any value as addr, what may result in an out-of-bounds access to array mdio_map. One existing case is stmmac_init_phy() that may pass -1 as addr. Therefore validate addr before using it.

VendorProductVersions

Linux

Linux

affected
7f854420fbfe9d49afe2ffb1df052cfe8e215541 - < 1d80c259dfbadefa61b7ea334dfce5cb57f8c72f
affected
7f854420fbfe9d49afe2ffb1df052cfe8e215541 - < c431a3d642593bbdb99e8a9e3eed608b730db6f8
affected
7f854420fbfe9d49afe2ffb1df052cfe8e215541 - < 8a7b9560a3a8eb8724888c426e05926752f73aa0
affected
7f854420fbfe9d49afe2ffb1df052cfe8e215541 - < 4bc5f1f6bc94e695dfd912122af96e7115a0ddb8
affected
7f854420fbfe9d49afe2ffb1df052cfe8e215541 - < ad67de330d83e8078372b52af18ffe8d39e26c85

+2 more versions

Linux

Linux

affected
4.5
unaffected
0 - < 4.5
unaffected
4.14.305 - <= 4.14.*
unaffected
4.19.272 - <= 4.19.*
unaffected
5.4.231 - <= 5.4.*

+4 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now