CVE-2023-52482
published 2024-02-29CVE-2023-52482: In the Linux kernel, the following vulnerability has been resolved: x86/srso: Add SRSO mitigation for Hygon processors Add mitigation for the speculative…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
x86/srso: Add SRSO mitigation for Hygon processors
Add mitigation for the speculative return stack overflow vulnerability
which exists on Hygon processors too.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | linux | < linux 6.1.64-1 (bookworm) | linux 6.1.64-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= c9661c1e80b609cd038db7c908e061f0535804ef < e7ea043bc3f19473561c08565047b3f1671bf35d | e7ea043bc3f19473561c08565047b3f1671bf35d |
| linux | linux | >= c9661c1e80b609cd038db7c908e061f0535804ef < f090a8b4d2e3ec6f318d6fdab243a2edc5a8cc37 | f090a8b4d2e3ec6f318d6fdab243a2edc5a8cc37 |
| linux | linux | >= c9661c1e80b609cd038db7c908e061f0535804ef < 6ce2f297a7168274547d0b5aea6c7c16268b8a96 | 6ce2f297a7168274547d0b5aea6c7c16268b8a96 |
| linux | linux | >= c9661c1e80b609cd038db7c908e061f0535804ef < cf43b304b6952b549d58feabc342807b334f03d4 | cf43b304b6952b549d58feabc342807b334f03d4 |
| linux | linux | >= c9661c1e80b609cd038db7c908e061f0535804ef < a5ef7d68cea1344cf524f04981c2b3f80bedbb0d | a5ef7d68cea1344cf524f04981c2b3f80bedbb0d |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.216-1 | 5.10.216-1 |
| linux | linux_kernel | >= 0 < 6.1.64-1 | 6.1.64-1 |
| linux | linux_kernel | >= 0 < 6.5.6-1 | 6.5.6-1 |
| linux | linux_kernel | >= 0 < 6.5.6-1 | 6.5.6-1 |
| linux | linux_kernel | >= 5.10.189 < 5.10.215 | 5.10.215 |
| linux | linux_kernel | >= 5.15.125 < 5.15.134 | 5.15.134 |
| linux | linux_kernel | >= 6.1.44 < 6.1.56 | 6.1.56 |
| linux | linux_kernel | >= 6.4.9 < 6.5.6 | 6.5.6 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wfpw-6p8q-8f6c: In the Linux kernel, the following vulnerability has been resolved:
x86/srso: Add SRSO mitigation for Hygon processors
Add mitigation for the specul
ghsa_unreviewed·2024-02-29
CVE-2023-52482 [HIGH] CWE-787 GHSA-wfpw-6p8q-8f6c: In the Linux kernel, the following vulnerability has been resolved:
x86/srso: Add SRSO mitigation for Hygon processors
Add mitigation for the specul
In the Linux kernel, the following vulnerability has been resolved:
x86/srso: Add SRSO mitigation for Hygon processors
Add mitigation for the speculative return stack overflow vulnerability
which exists on Hygon processors too.
OSV
CVE-2023-52482: In the Linux kernel, the following vulnerability has been resolved: x86/srso: Add SRSO mitigation for Hygon processors Add mitigation for the speculat
osv·2024-02-29·CVSS 7.8
CVE-2023-52482 [HIGH] CVE-2023-52482: In the Linux kernel, the following vulnerability has been resolved: x86/srso: Add SRSO mitigation for Hygon processors Add mitigation for the speculat
In the Linux kernel, the following vulnerability has been resolved: x86/srso: Add SRSO mitigation for Hygon processors Add mitigation for the speculative return stack overflow vulnerability which exists on Hygon processors too.
Red Hat
kernel: x86/srso: Add SRSO mitigation for Hygon processors
vendor_redhat·2024-02-29·CVSS 7.8
CVE-2023-52482 [HIGH] CWE-562 kernel: x86/srso: Add SRSO mitigation for Hygon processors
kernel: x86/srso: Add SRSO mitigation for Hygon processors
In the Linux kernel, the following vulnerability has been resolved:
x86/srso: Add SRSO mitigation for Hygon processors
Add mitigation for the speculative return stack overflow vulnerability
which exists on Hygon processors too.
A vulnerability was found in the Linux kernel, where the Hygon x86 processor is susceptible to a speculative return stack overflow.
Statement: This kernel vulnerability will not be addressed, as Hygon is not a x86 processor variant that Red Hat officially supports.
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Enterpri
Debian
CVE-2023-52482: linux - In the Linux kernel, the following vulnerability has been resolved: x86/srso: A...
vendor_debian·2023·CVSS 7.8
CVE-2023-52482 [HIGH] CVE-2023-52482: linux - In the Linux kernel, the following vulnerability has been resolved: x86/srso: A...
In the Linux kernel, the following vulnerability has been resolved: x86/srso: Add SRSO mitigation for Hygon processors Add mitigation for the speculative return stack overflow vulnerability which exists on Hygon processors too.
Scope: local
bookworm: resolved (fixed in 6.1.64-1)
bullseye: resolved (fixed in 5.10.216-1)
forky: resolved (fixed in 6.5.6-1)
sid: resolved (fixed in 6.5.6-1)
trixie: resolved (fixed in 6.5.6-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/6ce2f297a7168274547d0b5aea6c7c16268b8a96https://git.kernel.org/stable/c/a5ef7d68cea1344cf524f04981c2b3f80bedbb0dhttps://git.kernel.org/stable/c/cf43b304b6952b549d58feabc342807b334f03d4https://git.kernel.org/stable/c/e7ea043bc3f19473561c08565047b3f1671bf35dhttps://git.kernel.org/stable/c/f090a8b4d2e3ec6f318d6fdab243a2edc5a8cc37https://git.kernel.org/stable/c/6ce2f297a7168274547d0b5aea6c7c16268b8a96https://git.kernel.org/stable/c/a5ef7d68cea1344cf524f04981c2b3f80bedbb0dhttps://git.kernel.org/stable/c/cf43b304b6952b549d58feabc342807b334f03d4https://git.kernel.org/stable/c/e7ea043bc3f19473561c08565047b3f1671bf35dhttps://git.kernel.org/stable/c/f090a8b4d2e3ec6f318d6fdab243a2edc5a8cc37https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html
2024-02-29
Published