CVE-2023-52458

Public on 2024-02-23
Modified on 2024-04-24
Description
In the Linux kernel, the following vulnerability has been resolved:

block: add check that partition length needs to be aligned with block size

Before calling add partition or resize partition, there is no check
on whether the length is aligned with the logical block size.
If the logical block size of the disk is larger than 512 bytes,
then the partition size maybe not the multiple of the logical block size,
and when the last sector is read, bio_truncate() will adjust the bio size,
resulting in an IO error if the size of the read command is smaller than
the logical block size.If integrity data is supported, this will also
result in a null pointer dereference when calling bio_integrity_free.
Severity
Medium severity
Medium
CVSS v3 Base Score
5.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
HAQM Linux 1 kernel No Fix Planned
HAQM Linux 2 - Core kernel Pending Fix
HAQM Linux 2 - Kernel-5.4 Extra kernel Pending Fix
HAQM Linux 2 - Kernel-5.10 Extra kernel 2024-05-09 ALAS2KERNEL-5.10-2024-056 Fixed
HAQM Linux 2 - Kernel-5.10 Extra kernel 2024-08-01 ALAS2KERNEL-5.10-2024-068 Fixed
HAQM Linux 2 - Kernel-5.15 Extra kernel 2024-02-01 ALAS2KERNEL-5.15-2024-036 Fixed
HAQM Linux 2023 kernel 2024-02-15 ALAS2023-2024-519 Fixed

CVSS Scores

Score Type Score Vector
HAQM Linux CVSSv3 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD CVSSv3 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H