Junglewise Threat Intelligence

CVE-2023-53543: Linux Kernel OOB read in vDPA Netlink policy parsing

CVE-2023-53543 · Severity: high · CVSS 7.8 · Published 2025-10-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's vDPA (vhost Data Path Acceleration) framework, which is used to optimize network and storage performance in virtualized environments. A local attacker could exploit this flaw to cause a system crash or potentially access sensitive information from the kernel's memory. This issue affects the stability and security of systems running affected versions of the Linux kernel, particularly those utilizing high-performance virtualization features.

Technical details

An out-of-bounds (OOB) read vulnerability exists in the Linux kernel's vDPA (drivers/vdpa/vdpa.c) component. The root cause is a missing entry for the 'VDPA_ATTR_DEV_NET_CFG_MAX_VQP' attribute in the 'vdpa_nl_policy' structure. When parsing incoming Netlink messages (nlmsg), the kernel fails to validate the length of this specific attribute, leading to an invalid pointer in 'info->attrs'. A local attacker with low privileges can trigger this OOB read by sending a specially crafted Netlink message. This can result in a kernel panic (DoS) or the leakage of sensitive kernel memory. The issue has been patched in various stable branches including 6.1.47, 6.4.12, and the 6.5 release cycle.

Affected products

  • Linux Linux Kernel 5.15.198 to 6.1.47, 6.2 to 6.4.12, 6.5-rc1 to 6.5-rc6

Timeline

  • 2023-07-27: other: Initial patch submitted by Lin Ma
  • 2025-10-04: disclosed: CVE published by kernel.org

References

Related threats