PT-2025-54163 · Linux · Linux Kernel
Publicado
2023-02-01
·
Atualizado
2026-02-24
·
CVE-2023-54317
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A flaw exists in the Linux kernel where the zero page can be corrupted when using dm-flakey with corrupt bio writes enabled. This corruption occurs because the
blkdev issue zero pages function submits a write bio with a vector pointing to the zero page, and dm-flakey can corrupt this page. This can lead to crashes in userspace programs, as glibc assumes memory returned by mmap is zeroed and uses it for the calloc implementation. If the mapped memory is not zeroed, calloc may return non-zeroed memory.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Resource Release
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Linux Kernel