Junglewise Threat Intelligence

CVE-2023-54065: Linux kernel Realtek DSA driver out-of-bounds memory access

CVE-2023-54065 · Severity: high · CVSS 7.8 · Published 2025-12-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A Linux kernel driver for Realtek network switch chips fails to properly allocate memory for device-specific data in the MDIO interface probe function, leading to out-of-bounds memory writes. This memory corruption could cause system crashes, data corruption, or provide a foothold for privilege escalation on systems using affected Realtek network switches.

Technical details

The vulnerability is a heap buffer overflow in the realtek-mdio.c driver's probe function. The code sets priv->chip_data to a pointer immediately after the priv structure (void *)priv + sizeof(*priv), assuming adequate trailing space exists. However, only the realtek-smi variant allocated the required chip_data space; realtek-mdio did not, causing out-of-bounds writes when chip_data is accessed. The issue went undetected due to an unused 4096-byte buffer member in struct realtek_priv that caused memory allocators to round up and mask the overflow. The fix (commit b93eb564869321d0dffaf23fcc5c88112ed62466) changes realtek-mdio to properly allocate size_add(sizeof(*priv), var->chip_data_sz) bytes. The vulnerability affects systems with MDIO-attached Realtek switches, particularly those using alternative allocators or KASAN instrumentation.

Affected products

  • Linux Linux Kernel 5.x, 6.x versions prior to fix (commit b93eb564869321d0dffaf23fcc5c88112ed62466 from 2023-03-24)

Timeline

  • 2023-03-24: disclosed: Fix committed upstream
  • 2025-12-24: other: CVE-2023-54065 assigned and published in NVD

References

Related threats