First published: Tue Nov 21 2023(Updated: )
A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. Only privileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unrelated kernel memory, causing random kernel crashes and memory corruption.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | ||
Red Hat Fedora | =38 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6238 is a buffer overflow vulnerability in the NVM Express (NVMe) driver in the Linux kernel.
CVE-2023-6238 allows an unprivileged user to overwrite kernel memory, causing random kernel crashes.
CVE-2023-6238 has a high severity rating with a severity value of 7.
The NVM Express (NVMe) driver in the Linux kernel is affected by CVE-2023-6238.
Users are advised to update to the latest version of the Linux kernel that includes the security patch for CVE-2023-6238.