PT-2024-14768 · Linux+5 · Linux Kernel+5

Ran Xiaokai

+1

·

Published

2024-05-21

·

Updated

2026-05-26

·

CVE-2023-52831

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue occurs when a system has isolated CPUs via the "isolcpus=" command line parameter, and an attempt is made to offline the last housekeeping CPU. This results in a WARN ON() when rebuilding the scheduler domains and a subsequent panic due to an unhandled empty CPU mask in partition sched domains locked(). The functions cpuset hotplug workfn() and rebuild sched domains locked() are involved in this process. The cpumask and() function is used with doms[0], top cpuset.effective cpus, and housekeeping cpumask(HK FLAG DOMAIN).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Assertion Failure

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
BDU:2025-13366
CVE-2023-52831
INFSA-2024_9315
OESA-2024-1692
OESA-2024-1694
OPENSUSE-SU-2025_1177-1
OPENSUSE-SU-2025_1178-1
OPENSUSE-SU-2025_1180-1
RHSA-2024:9315
RHSA-2024_9315
SUSE-SU-2025:01919-1
SUSE-SU-2025:1177-1
SUSE-SU-2025:1178-1
SUSE-SU-2025:1180-1
SUSE-SU-2025:20190-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20260-1
SUSE-SU-2025:20270-1
SUSE-SU-2025_1177-1
SUSE-SU-2025_1178-1
SUSE-SU-2025_1180-1

Affected Products

Astra Linux
Debian
Linux Kernel
Red Hat
Red Os
Suse