目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2023-53570— Linux kernel 安全漏洞

AI 预测 4.7 利用难度: 困难 EPSS 0.15% · P5

影响版本矩阵 8

厂商产品版本范围状态
LinuxLinuxdc1e3cb8da8b414b37208b2fb6755fef8122504b< e642eb67b8c10dcce758d549cc81564116e0fa49affected
dc1e3cb8da8b414b37208b2fb6755fef8122504b< 7d09f9f255a5f78578deba5454923072bb53b16caffected
dc1e3cb8da8b414b37208b2fb6755fef8122504b< 6311071a056272e1e761de8d0305e87cc566f734affected
5.16affected
< 5.16unaffected
6.1.46≤ 6.1.*unaffected
6.4.11≤ 6.4.*unaffected
6.5≤ *unaffected
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2023-53570 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
wifi: nl80211: fix integer overflow in nl80211_parse_mbssid_elems()
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: fix integer overflow in nl80211_parse_mbssid_elems() nl80211_parse_mbssid_elems() uses a u8 variable num_elems to count the number of MBSSID elements in the nested netlink attribute attrs, which can lead to an integer overflow if a user of the nl80211 interface specifies 256 or more elements in the corresponding attribute in userspace. The integer overflow can lead to a heap buffer overflow as num_elems determines the size of the trailing array in elems, and this array is thereafter written to for each element in attrs. Note that this vulnerability only affects devices with the wiphy->mbssid_max_interfaces member set for the wireless physical device struct in the device driver, and can only be triggered by a process with CAP_NET_ADMIN capabilities. Fix this by checking for a maximum of 255 elements in attrs.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于nl80211_parse_mbssid_elems函数存在整数溢出,可能导致堆缓冲区溢出。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux dc1e3cb8da8b414b37208b2fb6755fef8122504b ~ e642eb67b8c10dcce758d549cc81564116e0fa49 -
LinuxLinux 5.16 -

二、漏洞 CVE-2023-53570 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2023-53570 的情报信息

登录查看更多情报信息。

CVE-2023-53570 补丁与修复 (3)

同批安全公告 · Linux · 2025-10-04 · 共 144 条

CVE-2025-399329.8 CRITICALLinux kernel 安全漏洞
CVE-2025-399489.8 CRITICALLinux kernel 安全漏洞
CVE-2025-399469.8 CRITICALLinux kernel 安全漏洞
CVE-2025-399339.4 CRITICALLinux kernel 安全漏洞
CVE-2025-399439.4 CRITICALLinux kernel 安全漏洞
CVE-2025-399528.8 HIGHLinux kernel 安全漏洞
CVE-2025-399317.8 HIGHLinux kernel 安全漏洞
CVE-2025-399517.8 HIGHLinux kernel 安全漏洞
CVE-2025-399497.8 HIGHLinux kernel 安全漏洞
CVE-2025-399457.8 HIGHLinux kernel 安全漏洞
CVE-2025-399447.8 HIGHLinux kernel 安全漏洞
CVE-2025-399417.8 HIGHLinux kernel 安全漏洞
CVE-2025-399397.8 HIGHLinux kernel 安全漏洞
CVE-2025-399357.8 HIGHLinux kernel 安全漏洞
CVE-2025-399427.5 HIGHLinux kernel 安全漏洞
CVE-2025-399297.5 HIGHLinux kernel 安全漏洞
CVE-2022-50505Linux kernel 安全漏洞
CVE-2022-50503Linux kernel 安全漏洞
CVE-2022-50501Linux kernel 安全漏洞
CVE-2022-50504Linux kernel 安全漏洞

显示前 20 条,共 144 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-53570

暂无评论


发表评论