CVE-2023-2194: Fedoraproject Fedora
Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.
An out-of-bounds write vulnerability was found in the Linux kernel's SLIMpro I2C device driver. The userspace "data->block[0]" variable was not capped to a number between 0-255 and was used as the size of a memcpy, possibly writing beyond the end of dma_buffer. This flaw could allow a local privileged user to crash the system or potentially achieve code execution.
Affected products
- Fedoraproject Fedora: version 38 only
- Linux Linux Kernel: before 6.3 (fixed in 6.3); version 6.3 only
- Red Hat Enterprise Linux: version 8.0 only; version 9.0 only
Published 2023-04-20. Last modified 2026-06-17.