CVE-2023-53817
Published: Dec 9, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: lib/mpi - avoid null pointer deref in mpi_cmp_ui() During NVMeTCP Authentication a controller can trigger a kernel oops by specifying the 8192 bit Diffie Hellman group and passing a correctly sized, but zeroed Diffie Hellamn value. mpi_cmp_ui() was detecting this if the second parameter was 0, but 1 is passed from dh_is_pubkey_valid(). This causes the null pointer u->d to be dereferenced towards the end of mpi_cmp_ui()
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 12f008b6dc5ff1c822fdb2198d20e3dbdc92f3f5 - < fde791e8a96a64ea7b0ad2440e43586447a209c6affected 12f008b6dc5ff1c822fdb2198d20e3dbdc92f3f5 - < ae63e84ffda74267bf7277c38415ba38389229a0affected 12f008b6dc5ff1c822fdb2198d20e3dbdc92f3f5 - < 61f5453e9706e99713825594e0c8f9031485fb5faffected 12f008b6dc5ff1c822fdb2198d20e3dbdc92f3f5 - < 0fc7147c694394f8a8cbc19570c6bc918cac0906affected 12f008b6dc5ff1c822fdb2198d20e3dbdc92f3f5 - < 67589d247909043e94d2dd5fb590958e0f99d58d+3 more versions |
Linux | Linux | affected 3.7unaffected 0 - < 3.7unaffected 4.14.326 - <= 4.14.*unaffected 4.19.295 - <= 4.19.*unaffected 5.4.257 - <= 5.4.*+5 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now