CVE-2023-53748
Published: Dec 8, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix potential array out-of-bounds in decoder queue_setup variable *nplanes is provided by user via system call argument. The possible value of q_data->fmt->num_planes is 1-3, while the value of *nplanes can be 1-8. The array access by index i can cause array out-of-bounds. Fix this bug by checking *nplanes against the array size.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 590577a4e5257ac3ed72999a94666ad6ba8f24bc - < 48e4e06e2c5fe1fda283d499f91492eda2248bb9affected 590577a4e5257ac3ed72999a94666ad6ba8f24bc - < b8e19bf3b4aebd855be01b64674187dcf6d1db51affected 590577a4e5257ac3ed72999a94666ad6ba8f24bc - < 8fbcf730cb89c3647f3365226fe7014118fa93c7 |
Linux | Linux | affected 4.10unaffected 0 - < 4.10unaffected 6.1.30 - <= 6.1.*unaffected 6.3.4 - <= 6.3.*unaffected 6.4 - <= * |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now