cbcvebase.
CVE-2023-52623
published 2024-03-26

CVE-2023-52623: In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix a suspicious RCU usage warning I received the following warning while running…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.28%
19.9th percentile
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix a suspicious RCU usage warning I received the following warning while running cthon against an ontap server running pNFS: [ 57.202521] ============================= [ 57.202522] WARNING: suspicious RCU usage [ 57.202523] 6.7.0-rc3-g2cc14f52aeb7 #41492 Not tainted [ 57.202525] ----------------------------- [ 57.202525] net/sunrpc/xprtmultipath.c:349 RCU-list traversed in non-reader section!! [ 57.202527] other info that might help us debug this: [ 57.202528] rcu_scheduler_active = 2, debug_locks = 1 [ 57.202529] no locks held by test5/3567. [ 57.202530] stack backtrace: [ 57.202532] CPU: 0 PID: 3567 Comm: test5 Not tainted 6.7.0-rc3-g2cc14f52aeb7 #41492 5b09971b4965c0aceba19f3eea324a4a806e227e [ 57.202534] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS unknown 2/2/2022 [ 57.202536] Call Trace: [ 57.202537] [ 57.202540] dump_stack_lvl+0x77/0xb0 [ 57.202551] lockdep_rcu_suspicious+0x154/0x1a0 [ 57.202556] rpc_xprt_switch_has_addr+0x17c/0x190 [sunrpc ebe02571b9a8ceebf7d98e71675af20c19bdb1f6] [ 57.202596] rpc_clnt_setup_test_and_add_xprt+0x50/0x180 [sunrpc ebe02571b9a8ceebf7d98e71675af20c19bdb1f6] [ 57.202621] ? rpc_clnt_add_xprt+0x254/0x300 [sunrpc ebe02571b9a8ceebf7d98e71675af20c19bdb1f6] [ 57.202646] rpc_clnt_add_xprt+0x27a/0x300 [sunrpc ebe02571b9a8ceebf7d98e71675af20c19bdb1f6] [ 57.202671] ? __pfx_rpc_clnt_setup_test_and_add_xprt+0x10/0x10 [sunrpc ebe02571b9a8ceebf7d98e71675af20c19bdb1f6] [ 57.202696] nfs4_pnfs_ds_connect+0x345/0x760 [nfsv4 c716d88496ded0ea6d289bbea684fa996f9b57a9] [ 57.202728] ? __pfx_nfs4_test_session_trunk+0x10/0x10 [nfsv4 c716d88496ded0ea6d289bbea684fa996f9b57a9] [ 57.202754] nfs4_fl_prepare_ds+0x75/0xc0 [nfs_layout_nfsv41_files e3a4187f18ae8a27b630f9feae6831b584a9360a] [ 57.202760] filelayout_write_pagelist+0x4a/0x200 [nfs_layout_nfsv41_files e3a4187f18ae8a27b630f9feae6831b584a9360a] [ 57.202765] pnfs_generic_pg_writepages+0xbe/0x230 [nfsv4 c716d88496d

Affected

24 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux>= 39e5d2df959dd4aea81fa33d765d2a5cc67a0512 < fece80a2a6718ed58487ce397285bb1b83a3e54efece80a2a6718ed58487ce397285bb1b83a3e54e
linuxlinux>= 39e5d2df959dd4aea81fa33d765d2a5cc67a0512 < 7a96d85bf196c170dcf1b47a82e9bb97cca69aa67a96d85bf196c170dcf1b47a82e9bb97cca69aa6
linuxlinux>= 39e5d2df959dd4aea81fa33d765d2a5cc67a0512 < c430e6bb43955c6bf573665fcebf31694925b9f7c430e6bb43955c6bf573665fcebf31694925b9f7
linuxlinux>= 39e5d2df959dd4aea81fa33d765d2a5cc67a0512 < f8cf4dabbdcb8bef85335b0ed7ad5b25fd82ff56f8cf4dabbdcb8bef85335b0ed7ad5b25fd82ff56
linuxlinux>= 39e5d2df959dd4aea81fa33d765d2a5cc67a0512 < e8ca3e73301e23e8c0ac0ce2e6bac4545cd776e0e8ca3e73301e23e8c0ac0ce2e6bac4545cd776e0
linuxlinux>= 39e5d2df959dd4aea81fa33d765d2a5cc67a0512 < 69c7eeb4f622c2a28da965f970f982db171f3dc669c7eeb4f622c2a28da965f970f982db171f3dc6
linuxlinux>= 39e5d2df959dd4aea81fa33d765d2a5cc67a0512 < 8f860c8407470baff2beb9982ad6b172c94f1d0a8f860c8407470baff2beb9982ad6b172c94f1d0a
linuxlinux>= 39e5d2df959dd4aea81fa33d765d2a5cc67a0512 < 31b62908693c90d4d07db597e685d9f25a12007331b62908693c90d4d07db597e685d9f25a120073
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 5.4.0-181.2015.4.0-181.201
linuxlinux_kernel>= 0 < 5.15.0-106.1165.15.0-106.116
linuxlinux_kernel>= 4.20 < 5.4.2695.4.269
linuxlinux_kernel>= 4.9 < 4.19.3074.19.307
linuxlinux_kernel>= 5.11 < 5.15.1495.15.149
linuxlinux_kernel>= 5.16 < 6.1.776.1.77
linuxlinux_kernel>= 5.5 < 5.10.2105.10.210
linuxlinux_kernel>= 6.2 < 6.6.166.6.16
linuxlinux_kernel>= 6.7 < 6.7.46.7.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.