modpost: fix off by one in is_executable_section()
Published Sep 18, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.14%
Description
The > comparison should be >= to prevent an out of bounds array access.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 4.1
Unaffected
- ≥ 0, < 4.1
- ≥ 4.14.322, ≤ 4.14.*
- ≥ 5.10.188, ≤ 5.10.*
- ≥ 5.15.121, ≤ 5.15.*
- ≥ 5.4.251, ≤ 5.4.*
- ≥ 6.1.39, ≤ 6.1.*
- ≥ 6.3.13, ≤ 6.3.*
- ≥ 6.4.4, ≤ 6.4.*
- 6.5
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | affected | Affected
Unaffected
|
- ≥ 4.1 · < 4.14.322
- ≥ 4.15 · < 5.4.251
- ≥ 5.5 · < 5.10.188
- ≥ 5.11 · < 5.15.121
- ≥ 5.16 · < 6.1.39
- ≥ 6.2 · < 6.3.13
- ≥ 6.4 · < 6.4.4
No data.
Red Hat Enterprise Linux 9
kernel-0:5.14.0-503.11.1.el9_5
Fixed · RHSA-2024:9315
Red Hat Enterprise Linux 9
kernel-0:5.14.0-503.11.1.el9_5
Fixed · RHSA-2024:9315
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-503.11.1.el9_5 | Fixed | RHSA-2024:9315 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-503.11.1.el9_5 | Fixed | RHSA-2024:9315 |
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (14)
- https://access.redhat.com/security/cve/CVE-2023-53397 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2396385 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-29955 Advisory
- https://git.kernel.org/stable/c/02dc8e8bdbe4412cfcf17ee3873e63fa5a55b957 Patch
- https://git.kernel.org/stable/c/3a3f1e573a105328a2cca45a7cfbebabbf5e3192 Patch
- https://git.kernel.org/stable/c/5e0424cd8a44b5f480feb06753cdf4e1f248d148 Patch
- https://git.kernel.org/stable/c/7ee557590bac154d324de446d1cd0444988bd511 Patch
- https://git.kernel.org/stable/c/8b2e77050b91199453bf19d0517b047b7339a9e3 Patch
- https://git.kernel.org/stable/c/cade370efe2f9e2a79ea8587506ffe2b51ac6d2b Patch
- https://git.kernel.org/stable/c/cb0cdca5c979bc34c27602e2039562932c2591a4 Patch
- https://git.kernel.org/stable/c/dd872d5576cc94528f427c7264c2c438928cc6d2 Patch
- https://lore.kernel.org/linux-cve-announce/2025091859-CVE-2023-53397-2076@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2023-53397
- https://www.cve.org/CVERecord?id=CVE-2023-53397
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data