CVE-2023-53817

Source
https://cve.org/CVERecord?id=CVE-2023-53817
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53817.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-53817
Downstream
Related
Published
2025-12-09T00:01:15.411Z
Modified
2026-03-20T02:59:10.149846Z
Summary
crypto: lib/mpi - avoid null pointer deref in mpi_cmp_ui()
Details

In the Linux kernel, the following vulnerability has been resolved:

crypto: lib/mpi - avoid null pointer deref in mpicmpui()

During NVMeTCP Authentication a controller can trigger a kernel oops by specifying the 8192 bit Diffie Hellman group and passing a correctly sized, but zeroed Diffie Hellamn value. mpicmpui() was detecting this if the second parameter was 0, but 1 is passed from dhispubkeyvalid(). This causes the null pointer u->d to be dereferenced towards the end of mpicmp_ui()

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53817.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
12f008b6dc5ff1c822fdb2198d20e3dbdc92f3f5
Fixed
fde791e8a96a64ea7b0ad2440e43586447a209c6
Fixed
ae63e84ffda74267bf7277c38415ba38389229a0
Fixed
61f5453e9706e99713825594e0c8f9031485fb5f
Fixed
0fc7147c694394f8a8cbc19570c6bc918cac0906
Fixed
67589d247909043e94d2dd5fb590958e0f99d58d
Fixed
d3ad023a39f1127dcfd331c562673355dc078650
Fixed
12ac013ad7ff0df066451e825801d805095b3776
Fixed
9e47a758b70167c9301d2b44d2569f86c7796f2d

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53817.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.7.0
Fixed
4.14.326
Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
4.19.295
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.257
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.197
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.133
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.55
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.5.5

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53817.json"