PT-2024-14596 · Linux+9 · Linux Kernel+9

Published

2023-12-29

·

Updated

2025-09-29

·

CVE-2023-52489

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A race condition in the Linux kernel's sparse memory management can cause a kernel crash when accessing memory section->usage. This issue occurs when the system memory configuration has PFNs (Page Frame Numbers) arranged as [ZONE NORMAL ZONE DEVICE ZONE NORMAL], and compaction is triggered on device memory PFNs. The crash logs are available, showing a kernel NULL pointer dereference at a virtual address. The issue is resolved by clearing SECTION HAS MEM MAP before freeing ->usage, using RCU protected read-side critical sections, and freeing ->usage with kfree rcu().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:2394
ALSA-2024:2950
ALSA-2024:3138
ALSA-2024_2394
ALSA-2025_16880
BDU:2025-03821
CESA-2024_2950
CESA-2024_3138
CVE-2023-52489
DLA-3842-1
DSA-5681-1
INFSA-2024_2394
INFSA-2024_2950
INFSA-2024_3138
OPENSUSE-SU-2024_3190-1
OPENSUSE-SU-2024_3209-1
OPENSUSE-SU-2024_3408-1
OPENSUSE-SU-2024_3483-1
OPENSUSE-SU-2025_0428-1
OPENSUSE-SU-2025_0499-1
RHSA-2024:10262
RHSA-2024:2394
RHSA-2024:2950
RHSA-2024:3138
RHSA-2024:6990
RHSA-2024:6991
RHSA-2024:8613
RHSA-2024:8614
RHSA-2024_2394
RHSA-2024_2950
RHSA-2024_3138
RLSA-2024:2950
RLSA-2024:3138
SUSE-SU-2024:3190-1
SUSE-SU-2024:3194-1
SUSE-SU-2024:3195-1
SUSE-SU-2024:3209-1
SUSE-SU-2024:3227-1
SUSE-SU-2024:3383-1
SUSE-SU-2024:3408-1
SUSE-SU-2024:3483-1
SUSE-SU-2024_3194-1
SUSE-SU-2024_3195-1
SUSE-SU-2024_3383-1
SUSE-SU-2025:0289-1
SUSE-SU-2025:0428-1
SUSE-SU-2025:0499-1
SUSE-SU-2025:20044-1
SUSE-SU-2025:20047-1
SUSE-SU-2025_0428-1
SUSE-SU-2025_0499-1
USN-6765-1
USN-6766-1
USN-6766-2
USN-6766-3
USN-6795-1
USN-6818-1
USN-6818-2
USN-6818-3
USN-6818-4
USN-6819-1
USN-6819-2
USN-6819-3
USN-6819-4
USN-6828-1

Affected Products

Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu