PT-2023-9481 · Linux+6 · Linux Kernel+6

Fei Yang

·

Publicado

2023-10-12

·

Atualizado

2025-09-29

·

CVE-2023-52504

CVSS v3.1

7.1

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the x86/alternatives component of the Linux kernel, where KASAN (Kernel Address Sanitizer) triggers during apply alternatives() on a 5-level paging machine, causing an out-of-bounds read in rcu is watching(). This occurs because KASAN gets confused when apply alternatives() patches the KASAN SHADOW START users. A test patch that makes KASAN SHADOW START static works around the issue. The problem is fixed by disabling KASAN while the kernel is patching alternatives.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2025_16880
ALT-PU-2023-6736
BDU:2024-07834
CVE-2023-52504
OESA-2024-1496
OESA-2024-1497
OESA-2024-1498
OESA-2024-1499
OESA-2024-1500
OESA-2024-1501
OPENSUSE-SU-2024_1321-1
OPENSUSE-SU-2024_1322-1
OPENSUSE-SU-2024_1322-2
OPENSUSE-SU-2024_1332-1
OPENSUSE-SU-2024_1332-2
OPENSUSE-SU-2024_1466-1
OPENSUSE-SU-2024_1480-1
OPENSUSE-SU-2024_1490-1
SUSE-SU-2024:1320-1
SUSE-SU-2024:1321-1
SUSE-SU-2024:1466-1
SUSE-SU-2024:1480-1
SUSE-SU-2024:1490-1
USN-6831-1
USN-6867-1

Produtos afetados

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu