CVE Published: 20/04/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: redhat |
Vendor: n/a |
Product: Linux kernel: i2c: xgene-slimpro Status : PUBLISHED
CVE-2023-2194 Description
An out-of-bounds write vulnerability was found in the Linux kernel\'s SLIMpro I2C device driver. The userspace "data->block[0]" variable was not capped to a number between 0-255 and was used as the size of a memcpy, possibly writing beyond the end of dma_buffer. This flaw could allow a local privileged user to crash the system or potentially achieve code execution.