cbcvebase.
CVE-2023-52615
published 2024-03-18

CVE-2023-52615: In the Linux kernel, the following vulnerability has been resolved: hwrng: core - Fix page fault dead lock on mmap-ed hwrng There is a dead-lock in the hwrng…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
9.4th percentile
In the Linux kernel, the following vulnerability has been resolved: hwrng: core - Fix page fault dead lock on mmap-ed hwrng There is a dead-lock in the hwrng device read path. This triggers when the user reads from /dev/hwrng into memory also mmap-ed from /dev/hwrng. The resulting page fault triggers a recursive read which then dead-locks. Fix this by using a stack buffer when calling copy_to_user.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux
linuxlinux>= 9996508b3353063f2d6c48c1a28a84543d72d70b < eafd83b92f6c044007a3591cbd476bcf90455990eafd83b92f6c044007a3591cbd476bcf90455990
linuxlinux>= 9996508b3353063f2d6c48c1a28a84543d72d70b < 5030d4c798863ccb266563201b341a099e8cdd485030d4c798863ccb266563201b341a099e8cdd48
linuxlinux>= 9996508b3353063f2d6c48c1a28a84543d72d70b < c6a8111aacbfe7a8a70f46cc0de8eed00561693cc6a8111aacbfe7a8a70f46cc0de8eed00561693c
linuxlinux>= 9996508b3353063f2d6c48c1a28a84543d72d70b < 26cc6d7006f922df6cc4389248032d955750b2a026cc6d7006f922df6cc4389248032d955750b2a0
linuxlinux>= 9996508b3353063f2d6c48c1a28a84543d72d70b < aa8aa16ed9adf1df05bb339d588cf485a011839eaa8aa16ed9adf1df05bb339d588cf485a011839e
linuxlinux>= 9996508b3353063f2d6c48c1a28a84543d72d70b < ecabe8cd456d3bf81e92c53b074732f3140f170decabe8cd456d3bf81e92c53b074732f3140f170d
linuxlinux>= 9996508b3353063f2d6c48c1a28a84543d72d70b < 6822a14271786150e178869f1495cc03e74c50296822a14271786150e178869f1495cc03e74c5029
linuxlinux>= 9996508b3353063f2d6c48c1a28a84543d72d70b < 78aafb3884f6bc6636efcc1760c891c8500b992278aafb3884f6bc6636efcc1760c891c8500b9922
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 5.4.0-181.2015.4.0-181.201
linuxlinux_kernel>= 0 < 5.15.0-106.1165.15.0-106.116
linuxlinux_kernel>= 0 < 4.4.0-256.2904.4.0-256.290
linuxlinux_kernel>= 0 < 4.15.0-226.2384.15.0-226.238
linuxlinux_kernel>= 2.6.33 < 4.19.3074.19.307
linuxlinux_kernel>= 4.20 < 5.4.2695.4.269
linuxlinux_kernel>= 5.11 < 5.15.1495.15.149
linuxlinux_kernel>= 5.16 < 6.1.766.1.76
linuxlinux_kernel>= 5.5 < 5.10.2105.10.210
linuxlinux_kernel>= 6.2 < 6.6.156.6.15
linuxlinux_kernel>= 6.7 < 6.7.36.7.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.