CVE-2023-53729: Linux
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: soc: qcom: qmi_encdec: Restrict string length in decode The QMI TLV value for strings in a lot of qmi element info structures account for null terminated strings with MAX_LEN + 1. If a string is actually MAX_LEN + 1 length, this will cause an out of bounds access when the NULL character is appended in decoding.
Affected products
- Linux Linux: from 4.16, before 4.19.295 (fixed in 4.19.295); from 4.20, before 5.4.257 (fixed in 5.4.257); from 5.5, before 5.10.195 (fixed in 5.10.195); from 5.11, before 5.15.132 (fixed in 5.15.132); from 5.16, before 6.1.54 (fixed in 6.1.54); from 6.2, before 6.5.4 (fixed in 6.5.4)
Published 2025-10-22. Last modified 2026-08-04.