cbcvebase.
CVE-2023-52522
published 2024-03-02

CVE-2023-52522: In the Linux kernel, the following vulnerability has been resolved: net: fix possible store tearing in neigh_periodic_work() While looking at a related syzbot…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.33%
25.7th percentile
In the Linux kernel, the following vulnerability has been resolved: net: fix possible store tearing in neigh_periodic_work() While looking at a related syzbot report involving neigh_periodic_work(), I found that I forgot to add an annotation when deleting an RCU protected item from a list. Readers use rcu_deference(*np), we need to use either rcu_assign_pointer() or WRITE_ONCE() on writer side to prevent store tearing. I use rcu_assign_pointer() to have lockdep support, this was the choice made in neigh_flush_dev().

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux>= 767e97e1e0db0d0f3152cd2f3bd3403596aedbad < 95eabb075a5902f4c0834ab1fb12dc35730c05af95eabb075a5902f4c0834ab1fb12dc35730c05af
linuxlinux>= 767e97e1e0db0d0f3152cd2f3bd3403596aedbad < 2ea52a2fb8e87067e26bbab4efb8872639240eb02ea52a2fb8e87067e26bbab4efb8872639240eb0
linuxlinux>= 767e97e1e0db0d0f3152cd2f3bd3403596aedbad < 147d89ee41434b97043c2dcb17a97dc151859baa147d89ee41434b97043c2dcb17a97dc151859baa
linuxlinux>= 767e97e1e0db0d0f3152cd2f3bd3403596aedbad < f82aac8162871e87027692b36af335a2375d4580f82aac8162871e87027692b36af335a2375d4580
linuxlinux>= 767e97e1e0db0d0f3152cd2f3bd3403596aedbad < a75152d233370362eebedb2643592e7c883cc9fca75152d233370362eebedb2643592e7c883cc9fc
linuxlinux>= 767e97e1e0db0d0f3152cd2f3bd3403596aedbad < 25563b581ba3a1f263a00e8c9a97f5e7363be6fd25563b581ba3a1f263a00e8c9a97f5e7363be6fd
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.205-15.10.205-1
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1
linuxlinux_kernel>= 0 < 6.5.8-16.5.8-1
linuxlinux_kernel>= 0 < 6.5.8-16.5.8-1
linuxlinux_kernel>= 0 < 4.4.0-266.3004.4.0-266.300
linuxlinux_kernel>= 0 < 4.15.0-235.2474.15.0-235.247
linuxlinux_kernel>= 2.6.37 < 5.4.2585.4.258
linuxlinux_kernel>= 5.11 < 5.15.1355.15.135
linuxlinux_kernel>= 5.16 < 6.1.576.1.57
linuxlinux_kernel>= 5.5 < 5.10.1985.10.198
linuxlinux_kernel>= 6.2 < 6.5.76.5.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.