block[0]" variable was not capped to a number between 0-255 and was used as the size of a memcpy, possibly writing beyond the end of dma_buffer. This flaw could allow a local privileged user to crash the system or potentially achieve code execution. "> block[0]",variable,was not,capped,to,a,number,between,0-255,and,was,used,as,the,size,of,a memcpy,,possibly,writing,beyond,the,end,of,dma_buffer.,This,flaw,could allow,a,local,privileged,user,to,crash,the,system,or,potentially achieve,code,execution. "> SecuritySpace - CVE-2023-2194
 
 
 Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2023-2194
Description:An out-of-bounds write vulnerability was found in the Linux kernel's SLIMpro I2C device driver. The userspace "data->block[0]" variable was not capped to a number between 0-255 and was used as the size of a memcpy, possibly writing beyond the end of dma_buffer. This flaw could allow a local privileged user to crash the system or potentially achieve code execution.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2023-2194
https://bugzilla.redhat.com/show_bug.cgi?id=2188396
https://bugzilla.redhat.com/show_bug.cgi?id=2188396
https://github.com/torvalds/linux/commit/92fbb6d1296f
https://github.com/torvalds/linux/commit/92fbb6d1296f
https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html
https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html




© 1998-2025 E-Soft Inc. All rights reserved.