PT-2023-9481 · Linux+6 · Linux Kernel+6

Fei Yang

·

Published

2023-10-12

·

Updated

2025-09-29

·

CVE-2023-52504

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the x86/alternatives component of the Linux kernel, where KASAN (Kernel Address Sanitizer) triggers during apply alternatives() on a 5-level paging machine, causing an out-of-bounds read in rcu is watching(). This occurs because KASAN gets confused when apply alternatives() patches the KASAN SHADOW START users. A test patch that makes KASAN SHADOW START static works around the issue. The problem is fixed by disabling KASAN while the kernel is patching alternatives.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2023-6736
BDU:2024-07834
CVE-2023-52504
OESA-2024-1496
OESA-2024-1497
OESA-2024-1498
OESA-2024-1499
OESA-2024-1500
OESA-2024-1501
OPENSUSE-SU-2024_1321-1
OPENSUSE-SU-2024_1322-1
OPENSUSE-SU-2024_1322-2
OPENSUSE-SU-2024_1332-1
OPENSUSE-SU-2024_1332-2
OPENSUSE-SU-2024_1466-1
OPENSUSE-SU-2024_1480-1
OPENSUSE-SU-2024_1490-1
SUSE-SU-2024:1320-1
SUSE-SU-2024:1321-1
SUSE-SU-2024:1466-1
SUSE-SU-2024:1480-1
SUSE-SU-2024:1490-1
USN-6831-1
USN-6867-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu