cbcvebase.
CVE-2023-52801
published 2024-05-21

CVE-2023-52801: In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix missing update of domains_itree after splitting iopt_area In…

PriorityP342critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
0.92%
56.4th percentile
In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix missing update of domains_itree after splitting iopt_area In iopt_area_split(), if the original iopt_area has filled a domain and is linked to domains_itree, pages_nodes have to be properly reinserted. Otherwise the domains_itree becomes corrupted and we will UAF.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.6.8-1 (forky)linux 6.6.8-1 (forky)
linuxlinux
linuxlinux>= 51fe6141f0f64ae0bbc096a41a07572273e8c0ef < 836db2e7e4565d8218923b3552304a1637e2f28d836db2e7e4565d8218923b3552304a1637e2f28d
linuxlinux>= 51fe6141f0f64ae0bbc096a41a07572273e8c0ef < fcb32111f01ddf3cbd04644cde1773428e31de6afcb32111f01ddf3cbd04644cde1773428e31de6a
linuxlinux>= 51fe6141f0f64ae0bbc096a41a07572273e8c0ef < e7250ab7ca4998fe026f2149805b03e09dc32498e7250ab7ca4998fe026f2149805b03e09dc32498
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 6.2 < 6.5.136.5.13
linuxlinux_kernel>= 6.6 < 6.6.36.6.3

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
osv9.1CRITICAL
vendor_debian9.1LOW
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.