CVE Database
/

CVE-2023-53748

Back to search

CVE-2023-53748

Published: Dec 8, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix potential array out-of-bounds in decoder queue_setup variable *nplanes is provided by user via system call argument. The possible value of q_data->fmt->num_planes is 1-3, while the value of *nplanes can be 1-8. The array access by index i can cause array out-of-bounds. Fix this bug by checking *nplanes against the array size.

VendorProductVersions

Linux

Linux

affected
590577a4e5257ac3ed72999a94666ad6ba8f24bc - < 48e4e06e2c5fe1fda283d499f91492eda2248bb9
affected
590577a4e5257ac3ed72999a94666ad6ba8f24bc - < b8e19bf3b4aebd855be01b64674187dcf6d1db51
affected
590577a4e5257ac3ed72999a94666ad6ba8f24bc - < 8fbcf730cb89c3647f3365226fe7014118fa93c7

Linux

Linux

affected
4.10
unaffected
0 - < 4.10
unaffected
6.1.30 - <= 6.1.*
unaffected
6.3.4 - <= 6.3.*
unaffected
6.4 - <= *

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now