PT-2025-38457 · Linux+4 · Linux Kernel+4

Published

2025-09-18

·

Updated

2026-05-26

·

CVE-2023-53438

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw within the x86/MCE subsystem related to handling Machine Check Exceptions (MCE) on AMD Zen-based systems. Specifically, the Instruction Fetch (IF) units may not always deliver a synchronous #MC for poison consumption errors, potentially leading to an incorrect severity grading of the error. This can result in unnecessary kernel panics when data poison errors occur, as the kernel may incorrectly assume the error originated in kernel context. The issue arises because the Code Segment (CS) register is not consistently saved during these errors. A quirk has been added to ensure the CS register is saved for poison consumption from the IF unit banks, enabling proper context determination.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

Weakness Enumeration

Related Identifiers

AZL-71924
BDU:2025-12413
CVE-2023-53438
OESA-2025-2406
OESA-2025-2407
OESA-2025-2408
SUSE-SU-2025:03600-1
SUSE-SU-2025:03613-1
SUSE-SU-2025:03614-1
SUSE-SU-2025:03615-1
SUSE-SU-2025:03626-1
SUSE-SU-2025:03628-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20851-1
SUSE-SU-2025:20861-1
SUSE-SU-2025:20870-1
SUSE-SU-2025:20898-1
SUSE-SU-2025:3716-1
SUSE-SU-2025:3751-1
SUSE-SU-2025:3761-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4141-1

Affected Products

Amd Zen
Astra Linux
Debian
Linux Kernel
Suse