CVE-2023-2194: Fedoraproject Fedora

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

An out-of-bounds write vulnerability was found in the Linux kernel's SLIMpro I2C device driver. The userspace "data->block[0]" variable was not capped to a number between 0-255 and was used as the size of a memcpy, possibly writing beyond the end of dma_buffer. This flaw could allow a local privileged user to crash the system or potentially achieve code execution.

Affected products

  • Fedoraproject Fedora: version 38 only
  • Linux Linux Kernel: before 6.3 (fixed in 6.3); version 6.3 only
  • Red Hat Enterprise Linux: version 8.0 only; version 9.0 only

Published 2023-04-20. Last modified 2026-06-17.