In the Linux kernel, the following vulnerability has been resolved:
ntbhwswitchtec: Fix shift-out-of-bounds in switchtecntbmwsettrans
There is a kernel API ntbmwcleartrans() would pass 0 to both addr and size. This would make xlatepos negative.
[ 23.734156] switchtec switchtec0: MW 0: part 0 addr 0x0000000000000000 size 0x0000000000000000 [ 23.734158] ================================================================================ [ 23.734172] UBSAN: shift-out-of-bounds in drivers/ntb/hw/mscc/ntbhwswitchtec.c:293:7 [ 23.734418] shift exponent -1 is negative
Ensuring xlate_pos is a positive or zero before BIT.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53034.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53034.json"
[
{
"signature_type": "Line",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@de203da734fae00e75be50220ba5391e7beecdf9",
"digest": {
"line_hashes": [
"292443880290703572225294448218450297588",
"26757319958389825450585445281854106477",
"271104384088244537398397143153004706977",
"268292259961244253563289829880393556225"
],
"threshold": 0.9
},
"id": "CVE-2023-53034-1cfb99f3",
"deprecated": false,
"target": {
"file": "drivers/ntb/hw/mscc/ntb_hw_switchtec.c"
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@cb153bdc1812a3375639ed6ca5f147eaefb65349",
"digest": {
"line_hashes": [
"292443880290703572225294448218450297588",
"26757319958389825450585445281854106477",
"271104384088244537398397143153004706977",
"268292259961244253563289829880393556225"
],
"threshold": 0.9
},
"id": "CVE-2023-53034-2a48dd7d",
"deprecated": false,
"target": {
"file": "drivers/ntb/hw/mscc/ntb_hw_switchtec.c"
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@de203da734fae00e75be50220ba5391e7beecdf9",
"digest": {
"function_hash": "201329879692013296208526547645266460773",
"length": 1440.0
},
"id": "CVE-2023-53034-55ba182f",
"deprecated": false,
"target": {
"file": "drivers/ntb/hw/mscc/ntb_hw_switchtec.c",
"function": "switchtec_ntb_mw_set_trans"
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c61a3f2df162ba424be0141649a9ef5f28eaccc1",
"digest": {
"function_hash": "201329879692013296208526547645266460773",
"length": 1440.0
},
"id": "CVE-2023-53034-7b86d93b",
"deprecated": false,
"target": {
"file": "drivers/ntb/hw/mscc/ntb_hw_switchtec.c",
"function": "switchtec_ntb_mw_set_trans"
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@cb153bdc1812a3375639ed6ca5f147eaefb65349",
"digest": {
"function_hash": "201329879692013296208526547645266460773",
"length": 1440.0
},
"id": "CVE-2023-53034-ae7dacf7",
"deprecated": false,
"target": {
"file": "drivers/ntb/hw/mscc/ntb_hw_switchtec.c",
"function": "switchtec_ntb_mw_set_trans"
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c61a3f2df162ba424be0141649a9ef5f28eaccc1",
"digest": {
"line_hashes": [
"292443880290703572225294448218450297588",
"26757319958389825450585445281854106477",
"271104384088244537398397143153004706977",
"268292259961244253563289829880393556225"
],
"threshold": 0.9
},
"id": "CVE-2023-53034-cba74f29",
"deprecated": false,
"target": {
"file": "drivers/ntb/hw/mscc/ntb_hw_switchtec.c"
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0df2e03e4620548b41891b4e0d1bd9d2e0d8a39a",
"digest": {
"function_hash": "201329879692013296208526547645266460773",
"length": 1440.0
},
"id": "CVE-2023-53034-da29e6b9",
"deprecated": false,
"target": {
"file": "drivers/ntb/hw/mscc/ntb_hw_switchtec.c",
"function": "switchtec_ntb_mw_set_trans"
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0df2e03e4620548b41891b4e0d1bd9d2e0d8a39a",
"digest": {
"line_hashes": [
"292443880290703572225294448218450297588",
"26757319958389825450585445281854106477",
"271104384088244537398397143153004706977",
"268292259961244253563289829880393556225"
],
"threshold": 0.9
},
"id": "CVE-2023-53034-ed10a456",
"deprecated": false,
"target": {
"file": "drivers/ntb/hw/mscc/ntb_hw_switchtec.c"
}
}
]