PT-2025-18831 · Linux+3 · Linux Kernel+3

Published

2023-02-25

·

Updated

2026-04-20

·

CVE-2023-53067

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to the fixed version
Description A vulnerability has been resolved in the Linux kernel. The issue is related to the LoongArch architecture and occurs when the get timer irq() function is called multiple times in the constant clockevent init() function. This can cause a sleeping function to be called from an invalid context, leading to a bug. The vulnerability is triggered when the might sleep() function is used in a preemption disable context. The estimated number of potentially affected devices is not specified.
Recommendations To resolve the issue, update the Linux kernel to a version that includes the fix. As a temporary workaround, consider modifying the constant clockevent init() function to only call get timer irq() once, using the timer irq installed variable as a check condition. Restrict access to the constant clockevent init() function to minimize the risk of exploitation. Avoid using the might sleep() function in a preemption disable context until the issue is resolved.

Exploit

Fix

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-03561
CVE-2023-53067

Affected Products

Astra Linux
Debian
Linux Kernel
Red Os