cbcvebase.
CVE-2023-52677
published 2024-05-17

CVE-2023-52677: In the Linux kernel, the following vulnerability has been resolved: riscv: Check if the code to patch lies in the exit section Otherwise we fall through to…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.2th percentile
In the Linux kernel, the following vulnerability has been resolved: riscv: Check if the code to patch lies in the exit section Otherwise we fall through to vmalloc_to_page() which panics since the address does not lie in the vmalloc region.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux
linuxlinux>= 043cb41a85de1c0e944da61ad7a264960e22c865 < 938f70d14618ec72e10d6fcf8a546134136d7c13938f70d14618ec72e10d6fcf8a546134136d7c13
linuxlinux>= 043cb41a85de1c0e944da61ad7a264960e22c865 < 890cfe5337e0aaf03ece1429db04d23c88da72e7890cfe5337e0aaf03ece1429db04d23c88da72e7
linuxlinux>= 043cb41a85de1c0e944da61ad7a264960e22c865 < 8db56df4a954b774bdc68917046a685a9fa2e4bc8db56df4a954b774bdc68917046a685a9fa2e4bc
linuxlinux>= 043cb41a85de1c0e944da61ad7a264960e22c865 < 1d7a03052846f34d624d0ab41a879adf5e85c85f1d7a03052846f34d624d0ab41a879adf5e85c85f
linuxlinux>= 043cb41a85de1c0e944da61ad7a264960e22c865 < 420370f3ae3d3b883813fd3051a38805160b2b9f420370f3ae3d3b883813fd3051a38805160b2b9f
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 5.16 < 6.1.756.1.75
linuxlinux_kernel>= 5.7 < 5.15.1485.15.148
linuxlinux_kernel>= 6.2 < 6.6.146.6.14
linuxlinux_kernel>= 6.7 < 6.7.26.7.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.