cbcvebase.
CVE-2023-52831
published 2024-05-21

CVE-2023-52831: In the Linux kernel, the following vulnerability has been resolved: cpu/hotplug: Don't offline the last non-isolated CPU If a system has isolated CPUs via the…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.1th percentile
In the Linux kernel, the following vulnerability has been resolved: cpu/hotplug: Don't offline the last non-isolated CPU If a system has isolated CPUs via the "isolcpus=" command line parameter, then an attempt to offline the last housekeeping CPU will result in a WARN_ON() when rebuilding the scheduler domains and a subsequent panic due to and unhandled empty CPU mas in partition_sched_domains_locked(). cpuset_hotplug_workfn() rebuild_sched_domains_locked() ndoms = generate_sched_domains(&doms, &attr); cpumask_and(doms[0], top_cpuset.effective_cpus, housekeeping_cpumask(HK_FLAG_DOMAIN)); Thus results in an empty CPU mask which triggers the warning and then the subsequent crash: WARNING: CPU: 4 PID: 80 at kernel/sched/topology.c:2366 build_sched_domains+0x120c/0x1408 Call trace: build_sched_domains+0x120c/0x1408 partition_sched_domains_locked+0x234/0x880 rebuild_sched_domains_locked+0x37c/0x798 rebuild_sched_domains+0x30/0x58 cpuset_hotplug_workfn+0x2a8/0x930 Unable to handle kernel paging request at virtual address fffe80027ab37080 partition_sched_domains_locked+0x318/0x880 rebuild_sched_domains_locked+0x37c/0x798 Aside of the resulting crash, it does not make any sense to offline the last last housekeeping CPU. Prevent this by masking out the non-housekeeping CPUs when selecting a target CPU for initiating the CPU unplug operation via the work queue.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 07f9e0c9987bf1c4ef57611ad2f789ba68978102 < 335a47ed71e332c82339d1aec0c7f6caccfcda13335a47ed71e332c82339d1aec0c7f6caccfcda13
linuxlinux>= 2b8272ff4a70b866106ae13c36be7ecbef5d5da2 < 3073f6df783d9d75f7f69f73e16c7ef85d6cfb633073f6df783d9d75f7f69f73e16c7ef85d6cfb63
linuxlinux>= 2b8272ff4a70b866106ae13c36be7ecbef5d5da2 < 38685e2a0476127db766f81b1c06019ddc4c9ffa38685e2a0476127db766f81b1c06019ddc4c9ffa
linuxlinux>= 6.1.53 < 6.1.646.1.64
linuxlinux>= 6.4.16 < 6.56.5
linuxlinux>= 6.5.3 < 6.5.136.5.13
linuxlinux>= fea9dd8653ff39ce383c54e747bde4c39289b4ad < 3410b702354702b500bde10e3cc1f9db8731d9083410b702354702b500bde10e3cc1f9db8731d908
linuxlinux_kernel< 6.1.646.1.64
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1
linuxlinux_kernel>= 0 < 6.5.13-16.5.13-1
linuxlinux_kernel>= 0 < 6.5.13-16.5.13-1
linuxlinux_kernel>= 6.2 < 6.5.136.5.13
linuxlinux_kernel>= 6.6 < 6.6.36.6.3
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.