CVE-2023-52813
published 2024-05-21CVE-2023-52813: In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix hungtask for PADATA_RESET We found a hungtask bug in test_aead_vec_cfg…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
20.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
crypto: pcrypt - Fix hungtask for PADATA_RESET
We found a hungtask bug in test_aead_vec_cfg as follows:
INFO: task cryptomgr_test:391009 blocked for more than 120 seconds.
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
Call trace:
__switch_to+0x98/0xe0
__schedule+0x6c4/0xf40
schedule+0xd8/0x1b4
schedule_timeout+0x474/0x560
wait_for_common+0x368/0x4e0
wait_for_completion+0x20/0x30
wait_for_completion+0x20/0x30
test_aead_vec_cfg+0xab4/0xd50
test_aead+0x144/0x1f0
alg_test_aead+0xd8/0x1e0
alg_test+0x634/0x890
cryptomgr_test+0x40/0x70
kthread+0x1e0/0x220
ret_from_fork+0x10/0x18
Kernel panic - not syncing: hung_task: blocked tasks
For padata_do_parallel, when the return err is 0 or -EBUSY, it will call
wait_for_completion(&wait->completion) in test_aead_vec_cfg. In normal
case, aead_request_complete() will be called in pcrypt_aead_serial and the
return err is 0 for padata_do_parallel. But, when pinst->flags is
PADATA_RESET, the return err is -EBUSY for padata_do_parallel, and it
won't call aead_request_complete(). Therefore, test_aead_vec_cfg will
hung at wait_for_completion(&wait->completion), which will cause
hungtask.
The problem comes as following:
(padata_do_parallel) |
rcu_read_lock_bh(); |
err = -EINVAL; | (padata_replace)
| pinst->flags |= PADATA_RESET;
err = -EBUSY |
if (pinst->flags & PADATA_RESET) |
rcu_read_unlock_bh() |
return err
In order to resolve the problem, we replace the return err -EBUSY with
-EAGAIN, which means parallel_data is changing, and the caller should call
it again.
v3:
remove retry and just change the return err.
v2:
introduce padata_try_do_parallel() in pcrypt_aead_encrypt and
pcrypt_aead_decrypt to solve the hungtask.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.64-1 (bookworm) | linux 6.1.64-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 16295bec6398a3eedc9377e1af6ff4c71b98c300 < fb2d3a50a8f29a3c66682bb426144f40e32ab818 | fb2d3a50a8f29a3c66682bb426144f40e32ab818 |
| linux | linux | >= 16295bec6398a3eedc9377e1af6ff4c71b98c300 < 039fec48e062504f14845124a1a25eb199b2ddc0 | 039fec48e062504f14845124a1a25eb199b2ddc0 |
| linux | linux | >= 16295bec6398a3eedc9377e1af6ff4c71b98c300 < c9c1334697301c10e6918d747ed38abfbc0c96e7 | c9c1334697301c10e6918d747ed38abfbc0c96e7 |
| linux | linux | >= 16295bec6398a3eedc9377e1af6ff4c71b98c300 < e97bf4ada7dddacd184c3e196bd063b0dc71b41d | e97bf4ada7dddacd184c3e196bd063b0dc71b41d |
| linux | linux | >= 16295bec6398a3eedc9377e1af6ff4c71b98c300 < 546c1796ad1ed0d87dab3c4b5156d75819be2316 | 546c1796ad1ed0d87dab3c4b5156d75819be2316 |
| linux | linux | >= 16295bec6398a3eedc9377e1af6ff4c71b98c300 < c55fc098fd9d2dca475b82d00ffbcaf97879d77e | c55fc098fd9d2dca475b82d00ffbcaf97879d77e |
| linux | linux | >= 16295bec6398a3eedc9377e1af6ff4c71b98c300 < e134f3aba98e6c801a693f540912c2d493718ddf | e134f3aba98e6c801a693f540912c2d493718ddf |
| linux | linux | >= 16295bec6398a3eedc9377e1af6ff4c71b98c300 < 372636debe852913529b1716f44addd94fff2d28 | 372636debe852913529b1716f44addd94fff2d28 |
| linux | linux | >= 16295bec6398a3eedc9377e1af6ff4c71b98c300 < 8f4f68e788c3a7a696546291258bfa5fdb215523 | 8f4f68e788c3a7a696546291258bfa5fdb215523 |
| linux | linux_kernel | >= 0 < 5.10.205-1 | 5.10.205-1 |
| linux | linux_kernel | >= 0 < 6.1.64-1 | 6.1.64-1 |
| linux | linux_kernel | >= 0 < 6.6.8-1 | 6.6.8-1 |
| linux | linux_kernel | >= 0 < 6.6.8-1 | 6.6.8-1 |
| linux | linux_kernel | >= 2.6.34 < 4.14.331 | 4.14.331 |
| linux | linux_kernel | >= 4.15 < 4.19.300 | 4.19.300 |
| linux | linux_kernel | >= 4.20 < 5.4.262 | 5.4.262 |
| linux | linux_kernel | >= 5.11 < 5.15.140 | 5.15.140 |
| linux | linux_kernel | >= 5.16 < 6.1.64 | 6.1.64 |
| linux | linux_kernel | >= 5.5 < 5.10.202 | 5.10.202 |
| linux | linux_kernel | >= 6.2 < 6.5.13 | 6.5.13 |
| linux | linux_kernel | >= 6.6 < 6.6.3 | 6.6.3 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SINEC OS
cisa_ics·2025-08-14
Siemens SINEC OS
ICS Advisory
##
Siemens SINEC OS
Release DateAugust 14, 2025
Alert CodeICSA-25-226-15
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3.1 9.1
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: RUGGEDCOM, SCALANCE
- Vulnerabilities: NULL Pointer Dereference, Use After Free, Unchecked Input for Loop Condition, Out-of-bounds Write, Ou
Red Hat
kernel: crypto: pcrypt - Fix hungtask for PADATA_RESET
vendor_redhat·2024-05-21·CVSS 5.5
CVE-2023-52813 [MEDIUM] CWE-833 kernel: crypto: pcrypt - Fix hungtask for PADATA_RESET
kernel: crypto: pcrypt - Fix hungtask for PADATA_RESET
In the Linux kernel, the following vulnerability has been resolved:
crypto: pcrypt - Fix hungtask for PADATA_RESET
We found a hungtask bug in test_aead_vec_cfg as follows:
INFO: task cryptomgr_test:391009 blocked for more than 120 seconds.
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
Call trace:
__switch_to+0x98/0xe0
__schedule+0x6c4/0xf40
schedule+0xd8/0x1b4
schedule_timeout+0x474/0x560
wait_for_common+0x368/0x4e0
wait_for_completion+0x20/0x30
wait_for_completion+0x20/0x30
test_aead_vec_cfg+0xab4/0xd50
test_aead+0x144/0x1f0
alg_test_aead+0xd8/0x1e0
alg_test+0x634/0x890
cryptomgr_test+0x40/0x70
kthread+0x1e0/0x220
ret_from_fork+0x10/0x18
Kernel panic - not syncing: hung_task: blocked tasks
For padata_do_pa
Debian
CVE-2023-52813: linux - In the Linux kernel, the following vulnerability has been resolved: crypto: pcr...
vendor_debian·2023·CVSS 5.5
CVE-2023-52813 [MEDIUM] CVE-2023-52813: linux - In the Linux kernel, the following vulnerability has been resolved: crypto: pcr...
In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix hungtask for PADATA_RESET We found a hungtask bug in test_aead_vec_cfg as follows: INFO: task cryptomgr_test:391009 blocked for more than 120 seconds. "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. Call trace: __switch_to+0x98/0xe0 __schedule+0x6c4/0xf40 schedule+0xd8/0x1b4 schedule_timeout+0x474/0x560 wait_for_common+0x368/0x4e0 wait_for_completion+0x20/0x30 wait_for_completion+0x20/0x30 test_aead_vec_cfg+0xab4/0xd50 test_aead+0x144/0x1f0 alg_test_aead+0xd8/0x1e0 alg_test+0x634/0x890 cryptomgr_test+0x40/0x70 kthread+0x1e0/0x220 ret_from_fork+0x10/0x18 Kernel panic - not syncing: hung_task: blocked tasks For padata_do_parallel, when the return err is 0 or -EBUSY, it will call
OSV
CVE-2023-52813: In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix hungtask for PADATA_RESET We found a hungtask bug in test_aea
osv·2024-05-21·CVSS 5.5
CVE-2023-52813 [MEDIUM] CVE-2023-52813: In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix hungtask for PADATA_RESET We found a hungtask bug in test_aea
In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix hungtask for PADATA_RESET We found a hungtask bug in test_aead_vec_cfg as follows: INFO: task cryptomgr_test:391009 blocked for more than 120 seconds. "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. Call trace: __switch_to+0x98/0xe0 __schedule+0x6c4/0xf40 schedule+0xd8/0x1b4 schedule_timeout+0x474/0x560 wait_for_common+0x368/0x4e0 wait_for_completion+0x20/0x30 wait_for_completion+0x20/0x30 test_aead_vec_cfg+0xab4/0xd50 test_aead+0x144/0x1f0 alg_test_aead+0xd8/0x1e0 alg_test+0x634/0x890 cryptomgr_test+0x40/0x70 kthread+0x1e0/0x220 ret_from_fork+0x10/0x18 Kernel panic - not syncing: hung_task: blocked tasks For padata_do_parallel, when the return err is 0 or -EBUSY, it will call
GHSA
GHSA-qwvj-ww5h-jh39: In the Linux kernel, the following vulnerability has been resolved:
crypto: pcrypt - Fix hungtask for PADATA_RESET
We found a hungtask bug in test_a
ghsa_unreviewed·2024-05-21
CVE-2023-52813 [MEDIUM] GHSA-qwvj-ww5h-jh39: In the Linux kernel, the following vulnerability has been resolved:
crypto: pcrypt - Fix hungtask for PADATA_RESET
We found a hungtask bug in test_a
In the Linux kernel, the following vulnerability has been resolved:
crypto: pcrypt - Fix hungtask for PADATA_RESET
We found a hungtask bug in test_aead_vec_cfg as follows:
INFO: task cryptomgr_test:391009 blocked for more than 120 seconds.
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
Call trace:
__switch_to+0x98/0xe0
__schedule+0x6c4/0xf40
schedule+0xd8/0x1b4
schedule_timeout+0x474/0x560
wait_for_common+0x368/0x4e0
wait_for_completion+0x20/0x30
wait_for_completion+0x20/0x30
test_aead_vec_cfg+0xab4/0xd50
test_aead+0x144/0x1f0
alg_test_aead+0xd8/0x1e0
alg_test+0x634/0x890
cryptomgr_test+0x40/0x70
kthread+0x1e0/0x220
ret_from_fork+0x10/0x18
Kernel panic - not syncing: hung_task: blocked tasks
For padata_do_parallel, when the return err is 0 or -EBUSY, it will
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/039fec48e062504f14845124a1a25eb199b2ddc0https://git.kernel.org/stable/c/372636debe852913529b1716f44addd94fff2d28https://git.kernel.org/stable/c/546c1796ad1ed0d87dab3c4b5156d75819be2316https://git.kernel.org/stable/c/8f4f68e788c3a7a696546291258bfa5fdb215523https://git.kernel.org/stable/c/c55fc098fd9d2dca475b82d00ffbcaf97879d77ehttps://git.kernel.org/stable/c/c9c1334697301c10e6918d747ed38abfbc0c96e7https://git.kernel.org/stable/c/e134f3aba98e6c801a693f540912c2d493718ddfhttps://git.kernel.org/stable/c/e97bf4ada7dddacd184c3e196bd063b0dc71b41dhttps://git.kernel.org/stable/c/fb2d3a50a8f29a3c66682bb426144f40e32ab818https://git.kernel.org/stable/c/039fec48e062504f14845124a1a25eb199b2ddc0https://git.kernel.org/stable/c/372636debe852913529b1716f44addd94fff2d28https://git.kernel.org/stable/c/546c1796ad1ed0d87dab3c4b5156d75819be2316https://git.kernel.org/stable/c/8f4f68e788c3a7a696546291258bfa5fdb215523https://git.kernel.org/stable/c/c55fc098fd9d2dca475b82d00ffbcaf97879d77ehttps://git.kernel.org/stable/c/c9c1334697301c10e6918d747ed38abfbc0c96e7https://git.kernel.org/stable/c/e134f3aba98e6c801a693f540912c2d493718ddfhttps://git.kernel.org/stable/c/e97bf4ada7dddacd184c3e196bd063b0dc71b41dhttps://git.kernel.org/stable/c/fb2d3a50a8f29a3c66682bb426144f40e32ab818
2024-05-21
Published