Junglewise Threat Intelligence

CVE-2023-53768: Linux kernel regmap-irq out-of-bounds access in buffer allocation

CVE-2023-53768 · Severity: high · CVSS 7.8 · Published 2025-12-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's interrupt request mapping (regmap-irq) component has a memory allocation bug that can cause system crashes due to out-of-bounds memory access. This affects devices using certain interrupt controller configurations and can lead to kernel crashes during device initialization, disrupting system operation and potentially creating security-relevant memory corruption scenarios.

Technical details

The vulnerability is a heap out-of-bounds write in the regmap_add_irq_chip_fwnode() function. The root cause is an incorrect loop termination condition when allocating a 2D array for IRQ type registers: the code allocates memory num_config_regs times instead of num_config_bases times, leading to extra heap writes when num_config_regs exceeds num_config_bases. The bug is triggered during early kernel initialization when IRQ chip drivers call regmap_add_irq_chip_fwnode() with mismatched configuration parameters. KASAN reports indicate memory corruption in the kernel memory allocator. This is a kernel-level bug requiring a patched kernel; the fix updates the loop condition to iterate num_config_bases times instead of num_config_regs times.

Affected products

  • Linux Linux Kernel Affected versions not specified in advisory; reportedly impacts devices such as db845c

Timeline

  • 2025-12-08: disclosed

Related threats