CVE-2023-53201
説明
CVE.org より
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: wraparound mbox producer index Driver is not handling the wraparound of the mbox producer index correctly. Currently the wraparound happens once u32 max is reached. Bit 31 of the producer index register is special and should be set only once for the first command. Because the producer index overflow setting bit31 after a long time, FW goes to initialization sequence and this causes FW hang. Fix is to wraparound the mbox producer index once it reaches u16 max.
詳細
The issue in the Broadcom bnxt_re RDMA driver was caused by incorrect handling of the mailbox producer index wraparound, which could eventually trigger firmware reinitialization. This results in a denial of service condition (firmware hang) but does not provide memory corruption or code execution capabilities. The flaw is only relevant on systems actively using the bnxt_re driver under sustained RDMA workloads.
CVSS (Common Vulnerability Scoring System) のスコアの詳細
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
以下の CSVV メトリクスおよびスコアは予備的で、再検討の対象となります。
CVSS v3 スコアの内訳
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| ベーススコア | 4.7 | 5.5 | N/A |
| 攻撃ベクトル | Local | Local | N/A |
| 攻撃の複雑さ | High | Low | N/A |
| 必要な権限 | Low | Low | N/A |
| ユーザー関与レベル | None | None | N/A |
| 範囲 | Unchanged | Unchanged | N/A |
| 機密性 | None | None | N/A |
| 完全性への影響 | None | None | N/A |
| 可用性への影響 | High | High | N/A |
ベクトル
Red Hat: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
脆弱性の原因 (CWE) の理解
Availability
Technical Impact: DoS: Crash, Exit, or Restart
If the incorrect calculation causes the program to move into an unexpected state, it may lead to a crash or impairment of service.
Integrity,Confidentiality,Availability
Technical Impact: DoS: Crash, Exit, or Restart; DoS: Resource Consumption (Other); Execute Unauthorized Code or Commands
If the incorrect calculation is used in the context of resource allocation, it could lead to an out-of-bounds operation (CWE-119) leading to a crash or even arbitrary code execution. Alternatively, it may result in an integer overflow (CWE-190) and / or a resource consumption problem (CWE-400).
Access Control
Technical Impact: Gain Privileges or Assume Identity
In the context of privilege or permissions assignment, an incorrect calculation can provide an attacker with access to sensitive resources.
Access Control
Technical Impact: Bypass Protection Mechanism
If the incorrect calculation leads to an insufficient comparison (CWE-697), it may compromise a protection mechanism such as a validation routine and allow an attacker to bypass the security-critical code.
よくある質問
Not sure what something means? Check out our Security Glossary.
エラータ通知の受信を希望しますか? こちらで登録してください。