CVE-2023-52707
published 2024-05-21CVE-2023-52707: In the Linux kernel, the following vulnerability has been resolved: sched/psi: Fix use-after-free in ep_remove_wait_queue() If a non-root cgroup gets removed…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
sched/psi: Fix use-after-free in ep_remove_wait_queue()
If a non-root cgroup gets removed when there is a thread that registered
trigger and is polling on a pressure file within the cgroup, the polling
waitqueue gets freed in the following path:
do_rmdir
cgroup_rmdir
kernfs_drain_open_files
cgroup_file_release
cgroup_pressure_release
psi_trigger_destroy
However, the polling thread still has a reference to the pressure file and
will access the freed waitqueue when the file is closed or upon exit:
fput
ep_eventpoll_release
ep_free
ep_remove_wait_queue
remove_wait_queue
This results in use-after-free as pasted below.
The fundamental problem here is that cgroup_file_release() (and
consequently waitqueue's lifetime) is not tied to the file's real lifetime.
Using wake_up_pollfree() here might be less than ideal, but it is in line
with the comment at commit 42288cb44c4b ("wait: add wake_up_pollfree()")
since the waitqueue's lifetime is not tied to file's one and can be
considered as another special case. While this would be fixable by somehow
making cgroup_file_release() be tied to the fput(), it would require
sizable refactoring at cgroups or higher layer which might be more
justifiable if we identify more cases like this.
BUG: KASAN: use-after-free in _raw_spin_lock_irqsave+0x60/0xc0
Write of size 4 at addr ffff88810e625328 by task a.out/4404
CPU: 19 PID: 4404 Comm: a.out Not tainted 6.2.0-rc6 #38
Hardware name: Amazon EC2 c5a.8xlarge/, BIOS 1.0 10/16/2017
Call Trace:
dump_stack_lvl+0x73/0xa0
print_report+0x16c/0x4e0
kasan_report+0xc3/0xf0
kasan_check_range+0x2d2/0x310
_raw_spin_lock_irqsave+0x60/0xc0
remove_wait_queue+0x1a/0xa0
ep_free+0x12c/0x170
ep_eventpoll_release+0x26/0x30
__fput+0x202/0x400
task_work_run+0x11d/0x170
do_exit+0x495/0x1130
do_group_exit+0x100/0x100
get_signal+0xd67/0xde0
arch_do_signal_or_restart+0x2a/0x2b0
exit_to_user_mode_prepare+0x94/0x100
syscall_exit_to_user_mode+0x20
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.15-1 (bookworm) | linux 6.1.15-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 0e94682b73bfa6c44c98af7a26771c9c08c055d5 < 7caeb5457bd01ccba0df1d6f4872f20d28e50b38 | 7caeb5457bd01ccba0df1d6f4872f20d28e50b38 |
| linux | linux | >= 0e94682b73bfa6c44c98af7a26771c9c08c055d5 < ec9c7aa08819f976b2492fa63c41b5712d2924b5 | ec9c7aa08819f976b2492fa63c41b5712d2924b5 |
| linux | linux | >= 0e94682b73bfa6c44c98af7a26771c9c08c055d5 < cca2b3feb70170ef6f0fbc4b4d91eea235a2b73a | cca2b3feb70170ef6f0fbc4b4d91eea235a2b73a |
| linux | linux | >= 0e94682b73bfa6c44c98af7a26771c9c08c055d5 < c6879a4dcefe92d870ab68cabaa9caeda4f2af5a | c6879a4dcefe92d870ab68cabaa9caeda4f2af5a |
| linux | linux | >= 0e94682b73bfa6c44c98af7a26771c9c08c055d5 < c2dbe32d5db5c4ead121cf86dabd5ab691fb47fe | c2dbe32d5db5c4ead121cf86dabd5ab691fb47fe |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.15-1 | 6.1.15-1 |
| linux | linux_kernel | >= 0 < 6.1.15-1 | 6.1.15-1 |
| linux | linux_kernel | >= 0 < 6.1.15-1 | 6.1.15-1 |
| linux | linux_kernel | >= 5.11 < 5.15.95 | 5.15.95 |
| linux | linux_kernel | >= 5.16 < 6.1.13 | 6.1.13 |
| linux | linux_kernel | >= 5.2 < 5.4.232 | 5.4.232 |
| linux | linux_kernel | >= 5.5 < 5.10.169 | 5.10.169 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cw5r-8wj2-xpqf: In the Linux kernel, the following vulnerability has been resolved:
sched/psi: Fix use-after-free in ep_remove_wait_queue()
If a non-root cgroup get
ghsa_unreviewed·2024-05-21
CVE-2023-52707 [HIGH] CWE-416 GHSA-cw5r-8wj2-xpqf: In the Linux kernel, the following vulnerability has been resolved:
sched/psi: Fix use-after-free in ep_remove_wait_queue()
If a non-root cgroup get
In the Linux kernel, the following vulnerability has been resolved:
sched/psi: Fix use-after-free in ep_remove_wait_queue()
If a non-root cgroup gets removed when there is a thread that registered
trigger and is polling on a pressure file within the cgroup, the polling
waitqueue gets freed in the following path:
do_rmdir
cgroup_rmdir
kernfs_drain_open_files
cgroup_file_release
cgroup_pressure_release
psi_trigger_destroy
However, the polling thread still has a reference to the pressure file and
will access the freed waitqueue when the file is closed or upon exit:
fput
ep_eventpoll_release
ep_free
ep_remove_wait_queue
remove_wait_queue
This results in use-after-free as pasted below.
The fundamental problem here is that cgroup_file_release() (and
consequently waitqueue's lifetime) is n
OSV
CVE-2023-52707: In the Linux kernel, the following vulnerability has been resolved: sched/psi: Fix use-after-free in ep_remove_wait_queue() If a non-root cgroup gets
osv·2024-05-21·CVSS 7.8
CVE-2023-52707 [HIGH] CVE-2023-52707: In the Linux kernel, the following vulnerability has been resolved: sched/psi: Fix use-after-free in ep_remove_wait_queue() If a non-root cgroup gets
In the Linux kernel, the following vulnerability has been resolved: sched/psi: Fix use-after-free in ep_remove_wait_queue() If a non-root cgroup gets removed when there is a thread that registered trigger and is polling on a pressure file within the cgroup, the polling waitqueue gets freed in the following path: do_rmdir cgroup_rmdir kernfs_drain_open_files cgroup_file_release cgroup_pressure_release psi_trigger_destroy However, the polling thread still has a reference to the pressure file and will access the freed waitqueue when the file is closed or upon exit: fput ep_eventpoll_release ep_free ep_remove_wait_queue remove_wait_queue This results in use-after-free as pasted below. The fundamental problem here is that cgroup_file_release() (and consequently waitqueue's lifetime) is not tied
Red Hat
kernel: sched/psi: Fix use-after-free in ep_remove_wait_queue()
vendor_redhat·2024-05-21·CVSS 7.8
CVE-2023-52707 [HIGH] CWE-416 kernel: sched/psi: Fix use-after-free in ep_remove_wait_queue()
kernel: sched/psi: Fix use-after-free in ep_remove_wait_queue()
In the Linux kernel, the following vulnerability has been resolved:
sched/psi: Fix use-after-free in ep_remove_wait_queue()
If a non-root cgroup gets removed when there is a thread that registered
trigger and is polling on a pressure file within the cgroup, the polling
waitqueue gets freed in the following path:
do_rmdir
cgroup_rmdir
kernfs_drain_open_files
cgroup_file_release
cgroup_pressure_release
psi_trigger_destroy
However, the polling thread still has a reference to the pressure file and
will access the freed waitqueue when the file is closed or upon exit:
fput
ep_eventpoll_release
ep_free
ep_remove_wait_queue
remove_wait_queue
This results in use-after-free as pasted below.
The fundamental problem here is that cgroup_f
Debian
CVE-2023-52707: linux - In the Linux kernel, the following vulnerability has been resolved: sched/psi: ...
vendor_debian·2023·CVSS 7.8
CVE-2023-52707 [HIGH] CVE-2023-52707: linux - In the Linux kernel, the following vulnerability has been resolved: sched/psi: ...
In the Linux kernel, the following vulnerability has been resolved: sched/psi: Fix use-after-free in ep_remove_wait_queue() If a non-root cgroup gets removed when there is a thread that registered trigger and is polling on a pressure file within the cgroup, the polling waitqueue gets freed in the following path: do_rmdir cgroup_rmdir kernfs_drain_open_files cgroup_file_release cgroup_pressure_release psi_trigger_destroy However, the polling thread still has a reference to the pressure file and will access the freed waitqueue when the file is closed or upon exit: fput ep_eventpoll_release ep_free ep_remove_wait_queue remove_wait_queue This results in use-after-free as pasted below. The fundamental problem here is that cgroup_file_release() (and consequently waitqueue's lifetime) is not tied
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/7caeb5457bd01ccba0df1d6f4872f20d28e50b38https://git.kernel.org/stable/c/c2dbe32d5db5c4ead121cf86dabd5ab691fb47fehttps://git.kernel.org/stable/c/c6879a4dcefe92d870ab68cabaa9caeda4f2af5ahttps://git.kernel.org/stable/c/cca2b3feb70170ef6f0fbc4b4d91eea235a2b73ahttps://git.kernel.org/stable/c/ec9c7aa08819f976b2492fa63c41b5712d2924b5https://git.kernel.org/stable/c/7caeb5457bd01ccba0df1d6f4872f20d28e50b38https://git.kernel.org/stable/c/c2dbe32d5db5c4ead121cf86dabd5ab691fb47fehttps://git.kernel.org/stable/c/c6879a4dcefe92d870ab68cabaa9caeda4f2af5ahttps://git.kernel.org/stable/c/cca2b3feb70170ef6f0fbc4b4d91eea235a2b73ahttps://git.kernel.org/stable/c/ec9c7aa08819f976b2492fa63c41b5712d2924b5
2024-05-21
Published