cbcvebase.
CVE-2023-52504
published 2024-03-02

CVE-2023-52504: In the Linux kernel, the following vulnerability has been resolved: x86/alternatives: Disable KASAN in apply_alternatives() Fei has reported that KASAN…

PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.27%
19.8th percentile
In the Linux kernel, the following vulnerability has been resolved: x86/alternatives: Disable KASAN in apply_alternatives() Fei has reported that KASAN triggers during apply_alternatives() on a 5-level paging machine: BUG: KASAN: out-of-bounds in rcu_is_watching() Read of size 4 at addr ff110003ee6419a0 by task swapper/0/0 ... __asan_load4() rcu_is_watching() trace_hardirqs_on() text_poke_early() apply_alternatives() ... On machines with 5-level paging, cpu_feature_enabled(X86_FEATURE_LA57) gets patched. It includes KASAN code, where KASAN_SHADOW_START depends on __VIRTUAL_MASK_SHIFT, which is defined with cpu_feature_enabled(). KASAN gets confused when apply_alternatives() patches the KASAN_SHADOW_START users. A test patch that makes KASAN_SHADOW_START static, by replacing __VIRTUAL_MASK_SHIFT with 56, works around the issue. Fix it for real by disabling KASAN while the kernel is patching alternatives. [ mingo: updated the changelog ]

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux>= 6657fca06e3ffab8d0b3f9d8b397f5ee498952d7 < 3719d3c36aa853d5a2401af9f8d6b116c91ad5ae3719d3c36aa853d5a2401af9f8d6b116c91ad5ae
linuxlinux>= 6657fca06e3ffab8d0b3f9d8b397f5ee498952d7 < 3770c38cd6a60494da29ac2da73ff8156440a2d13770c38cd6a60494da29ac2da73ff8156440a2d1
linuxlinux>= 6657fca06e3ffab8d0b3f9d8b397f5ee498952d7 < 6788b10620ca6e98575d1e06e72a8974aad7657e6788b10620ca6e98575d1e06e72a8974aad7657e
linuxlinux>= 6657fca06e3ffab8d0b3f9d8b397f5ee498952d7 < ecba5afe86f30605eb9dfb7f265a8de0218d4cfcecba5afe86f30605eb9dfb7f265a8de0218d4cfc
linuxlinux>= 6657fca06e3ffab8d0b3f9d8b397f5ee498952d7 < 5b784489c8158518bf7a466bb3cc045b0fb66b4b5b784489c8158518bf7a466bb3cc045b0fb66b4b
linuxlinux>= 6657fca06e3ffab8d0b3f9d8b397f5ee498952d7 < cd287cc208dfe6bd6da98e7f88e723209242c9b4cd287cc208dfe6bd6da98e7f88e723209242c9b4
linuxlinux>= 6657fca06e3ffab8d0b3f9d8b397f5ee498952d7 < d35652a5fc9944784f6f50a5c979518ff8dacf61d35652a5fc9944784f6f50a5c979518ff8dacf61
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.205-15.10.205-1
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1
linuxlinux_kernel>= 0 < 6.5.8-16.5.8-1
linuxlinux_kernel>= 0 < 6.5.8-16.5.8-1
linuxlinux_kernel>= 0 < 5.4.0-186.2065.4.0-186.206
linuxlinux_kernel>= 4.17 < 4.19.2974.19.297
linuxlinux_kernel>= 4.20 < 5.4.2705.4.270
linuxlinux_kernel>= 5.11 < 5.15.1365.15.136
linuxlinux_kernel>= 5.16 < 6.1.596.1.59
linuxlinux_kernel>= 5.5 < 5.10.1995.10.199
linuxlinux_kernel>= 6.2 < 6.5.86.5.8

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.