Review reviewHigh

CVE-2023-53819

Linux

In the Linux kernel, the following vulnerability has been resolved: amdgpu: validate offset_in_bo of drm_amdgpu_gem_va This is motivated by OOB access in amdgpu_vm_update_range when offset_in_bo+map_size overflows. v2: keep the validations in amdgpu_vm_bo_map v3: add the validations to amdgpu_vm_bo_map/amdgpu_vm_bo_replace_map rather than to amdgpu_gem_va_ioctl

CVSS
7.8
EPSS
0.13%
2.81% percentile
CISA KEV
Not listed
Published
2025.12.09
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.13%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: amdgpu: validate offset_in_bo of drm_amdgpu_gem_va This is motivated by OOB access in amdgpu_vm_update_range when offset_in_bo+map_size overflows. v2: keep the validations in amdgpu_vm_bo_map v3: add the validations to amdgpu_vm_bo_map/amdgpu_vm_bo_replace_map rather than to amdgpu_gem_va_ioctl

Affected product and versions

Product
Linux
Affected versions
>= 9f7eb5367d0001536c361bd1400e14521f854ff1 < 82aace80cfaab778245bd2f9e31b67953725e4d0, >= 9f7eb5367d0001536c361bd1400e14521f854ff1 < d83c337e654d58d3edd15a2ae76e87dc601c07d9, >= 9f7eb5367d0001536c361bd1400e14521f854ff1 < 968e27fd037ec4732068820a9b9836eccc0e0a12, >= 9f7eb5367d0001536c361bd1400e14521f854ff1 < 4300a47e4017c9febb60ffa7d39723eeaed00f2b, >= 9f7eb5367d0001536c361bd1400e14521f854ff1 < b10db1d2137415e5e7f9706d96cfe77539c499d4, >= 9f7eb5367d0001536c361bd1400e14521f854ff1 < f015aadc0d973047f49526a127e900c488d4e425, >= 9f7eb5367d0001536c361bd1400e14521f854ff1 < bc6dbf34dc4fb639522f3e8e66ef05997c0441ee, >= 9f7eb5367d0001536c361bd1400e14521f854ff1 < 9f0bcf49e9895cb005d78b33a5eebfa11711b425, >= 4.2
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2023-53819 — Linux | SECUFOCUS NOW