PT-2025-13340 · Linux+4 · Linux Kernel+4

Published

2023-01-17

·

Updated

2025-09-29

·

CVE-2023-52994

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to the version containing commit f1e525009493
Description A vulnerability in the Linux kernel has been resolved, related to the Advanced Configuration and Power Interface (ACPI) handling when suspending the system under Xen PV. The issue arises from a missed code path accessing real mode header, leading to a NULL pointer dereference when suspending the system. This results in a kernel crash, as indicated by the BUG: kernel NULL pointer dereference message. The vulnerability is fixed by adding an optional ACPI callback to skip setting the wakeup address, which is handled by the hypervisor in the Xen PV case.
Recommendations For Linux kernel versions prior to the version containing commit f1e525009493, update to a version that includes the fix for the ACPI suspend issue with Xen PV. As a temporary workaround, consider disabling suspend functionality until a patched version is available. Restrict access to the acpi get wakeup address function to minimize the risk of exploitation. Avoid using the real mode header variable in sensitive code paths until the issue is resolved.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2025-06233
CVE-2023-52994
OPENSUSE-SU-2025_01620-1
OPENSUSE-SU-2025_01640-1
RHSA-2023:6583
RHSA-2023_6583
SUSE-SU-2025:01620-1
SUSE-SU-2025:01640-1
SUSE-SU-2025_01620-1

Affected Products

Astra Linux
Linux Kernel
Red Hat
Red Os
Suse