CVE-2023-52619 — Resource Injection in Linux
Severity
5.5MEDIUMNVD
OSV7.5OSV6.5
EPSS
0.0%
top 96.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 18
Latest updateAug 14
Description
In the Linux kernel, the following vulnerability has been resolved:
pstore/ram: Fix crash when setting number of cpus to an odd number
When the number of cpu cores is adjusted to 7 or other odd numbers,
the zone size will become an odd number.
The address of the zone will become:
addr of zone0 = BASE
addr of zone1 = BASE + zone_size
addr of zone2 = BASE + zone_size*2
...
The address of zone1/3/5/7 will be mapped to non-alignment va.
Eventually crashes will occur when accessing these va.
So, u…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages5 packages
▶CVEListV5linux/linuxde83209249d64bad993f25d3ea4bba57683e2e2e — 8b69c30f4e8b69131d92096cb296dc1f217101e4+8
Also affects: Debian Linux 10.0
Patches
🔴Vulnerability Details
18📋Vendor Advisories
18💬Community
1Bugzilla▶
CVE-2023-52619 kernel: pstore/ram: Fix crash when setting number of cpus to an odd number↗2024-03-18