Kernel: nvme: memory corruption via unprivileged user passthrough
CVE-2023-6238
6.7MEDIUM
What is CVE-2023-6238?
A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. Only privileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unrelated kernel memory, causing random kernel crashes and memory corruption.