CVE-2023-53748

Source
https://cve.org/CVERecord?id=CVE-2023-53748
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53748.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-53748
Downstream
Related
Published
2025-12-08T01:19:07.318Z
Modified
2026-04-02T09:45:03.772820Z
Summary
media: mediatek: vcodec: Fix potential array out-of-bounds in decoder queue_setup
Details

In the Linux kernel, the following vulnerability has been resolved:

media: mediatek: vcodec: Fix potential array out-of-bounds in decoder queue_setup

variable *nplanes is provided by user via system call argument. The possible value of qdata->fmt->numplanes is 1-3, while the value of *nplanes can be 1-8. The array access by index i can cause array out-of-bounds.

Fix this bug by checking *nplanes against the array size.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53748.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
590577a4e5257ac3ed72999a94666ad6ba8f24bc
Fixed
48e4e06e2c5fe1fda283d499f91492eda2248bb9
Fixed
b8e19bf3b4aebd855be01b64674187dcf6d1db51
Fixed
8fbcf730cb89c3647f3365226fe7014118fa93c7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53748.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.10.0
Fixed
6.1.30
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.3.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53748.json"