CVE-2023-52766: Linux Kernel
High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: i3c: mipi-i3c-hci: Fix out of bounds access in hci_dma_irq_handler Do not loop over ring headers in hci_dma_irq_handler() that are not allocated and enabled in hci_dma_init(). Otherwise out of bounds access will occur from rings->headers[i] access when i >= number of allocated ring headers.
Affected products
- Linux Linux Kernel: before 5.15.140 (fixed in 5.15.140); from 5.16, before 6.1.64 (fixed in 6.1.64); from 6.2, before 6.5.13 (fixed in 6.5.13); from 6.6, before 6.6.3 (fixed in 6.6.3)
Published 2024-05-21. Last modified 2026-08-04.