cve/2023/CVE-2023-52626.md
2024-05-28 08:49:17 +00:00

948 B

CVE-2023-52626

Description

In the Linux kernel, the following vulnerability has been resolved:net/mlx5e: Fix operation precedence bug in port timestamping napi_poll contextIndirection (*) is of lower precedence than postfix increment (++). Logicin napi_poll context would cause an out-of-bound read by first incrementthe pointer address by byte address space and then dereference the value.Rather, the intended logic was to dereference first and then increment theunderlying value.

POC

Reference

No PoCs from references.

Github