cbcvebase.
CVE-2023-52578
published 2024-03-02

CVE-2023-52578: In the Linux kernel, the following vulnerability has been resolved: net: bridge: use DEV_STATS_INC() syzbot/KCSAN reported data-races in…

PriorityP431high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.19%
8.9th percentile
In the Linux kernel, the following vulnerability has been resolved: net: bridge: use DEV_STATS_INC() syzbot/KCSAN reported data-races in br_handle_frame_finish() [1] This function can run from multiple cpus without mutual exclusion. Adopt SMP safe DEV_STATS_INC() to update dev->stats fields. Handles updates to dev->stats.tx_dropped while we are at it. [1] BUG: KCSAN: data-race in br_handle_frame_finish / br_handle_frame_finish read-write to 0xffff8881374b2178 of 8 bytes by interrupt on cpu 1: br_handle_frame_finish+0xd4f/0xef0 net/bridge/br_input.c:189 br_nf_hook_thresh+0x1ed/0x220 br_nf_pre_routing_finish_ipv6+0x50f/0x540 NF_HOOK include/linux/netfilter.h:304 [inline] br_nf_pre_routing_ipv6+0x1e3/0x2a0 net/bridge/br_netfilter_ipv6.c:178 br_nf_pre_routing+0x526/0xba0 net/bridge/br_netfilter_hooks.c:508 nf_hook_entry_hookfn include/linux/netfilter.h:144 [inline] nf_hook_bridge_pre net/bridge/br_input.c:272 [inline] br_handle_frame+0x4c9/0x940 net/bridge/br_input.c:417 __netif_receive_skb_core+0xa8a/0x21e0 net/core/dev.c:5417 __netif_receive_skb_one_core net/core/dev.c:5521 [inline] __netif_receive_skb+0x57/0x1b0 net/core/dev.c:5637 process_backlog+0x21f/0x380 net/core/dev.c:5965 __napi_poll+0x60/0x3b0 net/core/dev.c:6527 napi_poll net/core/dev.c:6594 [inline] net_rx_action+0x32b/0x750 net/core/dev.c:6727 __do_softirq+0xc1/0x265 kernel/softirq.c:553 run_ksoftirqd+0x17/0x20 kernel/softirq.c:921 smpboot_thread_fn+0x30a/0x4a0 kernel/smpboot.c:164 kthread+0x1d7/0x210 kernel/kthread.c:388 ret_from_fork+0x48/0x60 arch/x86/kernel/process.c:147 ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:304 read-write to 0xffff8881374b2178 of 8 bytes by interrupt on cpu 0: br_handle_frame_finish+0xd4f/0xef0 net/bridge/br_input.c:189 br_nf_hook_thresh+0x1ed/0x220 br_nf_pre_routing_finish_ipv6+0x50f/0x540 NF_HOOK include/linux/netfilter.h:304 [inline] br_nf_pre_routing_ipv6+0x1e3/0x2a0 net/bridge/br_netfilter_ipv6.c:178 br_nf_pre_routing+0x526/0xba0 net/bridge/br_netfilter_hoo

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux>= 1c29fc4989bc2a3838b2837adc12b8aeb0feeede < d2346e6beb699909ca455d9d20c4e577ce900839d2346e6beb699909ca455d9d20c4e577ce900839
linuxlinux>= 1c29fc4989bc2a3838b2837adc12b8aeb0feeede < ad8d39c7b437fcdab7208a6a56c093d222c008d5ad8d39c7b437fcdab7208a6a56c093d222c008d5
linuxlinux>= 1c29fc4989bc2a3838b2837adc12b8aeb0feeede < 04cc361f029c14dd067ad180525c7392334c9bfd04cc361f029c14dd067ad180525c7392334c9bfd
linuxlinux>= 1c29fc4989bc2a3838b2837adc12b8aeb0feeede < 8bc97117b51d68d5cea8f5351cca2d8c4153f3948bc97117b51d68d5cea8f5351cca2d8c4153f394
linuxlinux>= 1c29fc4989bc2a3838b2837adc12b8aeb0feeede < 89f9f20b1cbd36d99d5a248a4bf8d11d4fd049a289f9f20b1cbd36d99d5a248a4bf8d11d4fd049a2
linuxlinux>= 1c29fc4989bc2a3838b2837adc12b8aeb0feeede < f2ef4cb4d418fa64fe73eb84d10cc5c0e52e00faf2ef4cb4d418fa64fe73eb84d10cc5c0e52e00fa
linuxlinux>= 1c29fc4989bc2a3838b2837adc12b8aeb0feeede < 44bdb313da57322c9b3c108eb66981c6ec6509f444bdb313da57322c9b3c108eb66981c6ec6509f4
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.205-15.10.205-1
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1
linuxlinux_kernel>= 0 < 6.5.6-16.5.6-1
linuxlinux_kernel>= 0 < 6.5.6-16.5.6-1
linuxlinux_kernel>= 0 < 4.4.0-261.2954.4.0-261.295
linuxlinux_kernel>= 0 < 4.15.0-231.2434.15.0-231.243
linuxlinux_kernel>= 2.6.17 < 4.19.2964.19.296
linuxlinux_kernel>= 4.20 < 5.4.2585.4.258
linuxlinux_kernel>= 5.11 < 5.15.1345.15.134
linuxlinux_kernel>= 5.16 < 6.1.566.1.56
linuxlinux_kernel>= 5.5 < 5.10.1985.10.198
linuxlinux_kernel>= 6.2 < 6.5.66.5.6

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.