PT-2024-14670 · Linux+5 · Linux Kernel+5

Vincent Whitchurch

·

Published

2024-01-05

·

Updated

2026-03-14

·

CVE-2023-52633

CVSS v3.1

5.0

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.15.149 Linux kernel versions prior to 6.1.77 Linux kernel versions prior to 6.6.16 Linux kernel versions prior to 6.7.4
Description The issue is related to time corruption in the Linux kernel's 'basic' time-travel mode. Timer interrupts can occur at arbitrary points, causing time to go backwards and resulting in a crash. The problem arises when the interrupt happens after calculating the new time but before finishing the adjustment. To fix this, the time travel time is read, the adjustment is calculated, and the adjustment is made with interrupts disabled. The timer read function is involved in this process.
Recommendations For Linux kernel versions prior to 5.15.149, update to version 5.15.149 or later. For Linux kernel versions prior to 6.1.77, update to version 6.1.77 or later. For Linux kernel versions prior to 6.6.16, update to version 6.6.16 or later. For Linux kernel versions prior to 6.7.4, update to version 6.7.4 or later. As a temporary workaround, consider disabling the timer read function until a patch is available. Restrict access to the vulnerable time-travel mode to minimize the risk of exploitation. Avoid using the time travel time variable in the affected API endpoint until the issue is resolved.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-15084
CVE-2023-52633
DSA-5658-1
OESA-2024-1622
OESA-2024-1647
OESA-2024-1648
OESA-2024-1649
USN-6765-1
USN-6766-1
USN-6766-2
USN-6766-3
USN-6795-1
USN-6818-1
USN-6818-2
USN-6818-3
USN-6818-4
USN-6819-1
USN-6819-2
USN-6819-3
USN-6819-4
USN-6828-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Ubuntu