{"id":"DEBIAN-CVE-2023-53272","details":"In the Linux kernel, the following vulnerability has been resolved:  net: ena: fix shift-out-of-bounds in exponential backoff  The ENA adapters on our instances occasionally reset.  Once recently logged a UBSAN failure to console in the process:    UBSAN: shift-out-of-bounds in build/linux/drivers/net/ethernet/amazon/ena/ena_com.c:540:13   shift exponent 32 is too large for 32-bit type 'unsigned int'   CPU: 28 PID: 70012 Comm: kworker/u72:2 Kdump: loaded not tainted 5.15.117   Hardware name: Amazon EC2 c5d.9xlarge/, BIOS 1.0 10/16/2017   Workqueue: ena ena_fw_reset_device [ena]   Call Trace:   \u003cTASK\u003e   dump_stack_lvl+0x4a/0x63   dump_stack+0x10/0x16   ubsan_epilogue+0x9/0x36   __ubsan_handle_shift_out_of_bounds.cold+0x61/0x10e   ? __const_udelay+0x43/0x50   ena_delay_exponential_backoff_us.cold+0x16/0x1e [ena]   wait_for_reset_state+0x54/0xa0 [ena]   ena_com_dev_reset+0xc8/0x110 [ena]   ena_down+0x3fe/0x480 [ena]   ena_destroy_device+0xeb/0xf0 [ena]   ena_fw_reset_device+0x30/0x50 [ena]   process_one_work+0x22b/0x3d0   worker_thread+0x4d/0x3f0   ? process_one_work+0x3d0/0x3d0   kthread+0x12a/0x150   ? set_kthread_struct+0x50/0x50   ret_from_fork+0x22/0x30   \u003c/TASK\u003e  Apparently, the reset delays are getting so large they can trigger a UBSAN panic.  Looking at the code, the current timeout is capped at 5000us.  Using a base value of 100us, the current code will overflow after (1\u003c\u003c29).  Even at values before 32, this function wraps around, perhaps unintentionally.  Cap the value of the exponent used for this backoff at (1\u003c\u003c16) which is larger than currently necessary, but large enough to support bigger values in the future.","modified":"2026-09-15T09:02:50.894907218Z","published":"2025-09-16T08:15:36.013Z","upstream":["CVE-2023-53272"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-53272"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.52-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53272.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53272.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53272.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"}]}