cbcvebase.
CVE-2023-52932
published 2025-03-27

CVE-2023-52932: In the Linux kernel, the following vulnerability has been resolved: mm/swapfile: add cond_resched() in get_swap_pages() The softlockup still occurs in…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
9.6th percentile
In the Linux kernel, the following vulnerability has been resolved: mm/swapfile: add cond_resched() in get_swap_pages() The softlockup still occurs in get_swap_pages() under memory pressure. 64 CPU cores, 64GB memory, and 28 zram devices, the disksize of each zram device is 50MB with same priority as si. Use the stress-ng tool to increase memory pressure, causing the system to oom frequently. The plist_for_each_entry_safe() loops in get_swap_pages() could reach tens of thousands of times to find available space (extreme case: cond_resched() is not called in scan_swap_map_slots()). Let's add cond_resched() into get_swap_pages() when failed to find available space to avoid softlockup.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.11-1 (bookworm)linux 6.1.11-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 3.12.30 < 3.133.13
linuxlinux>= 3.14.21 < 3.153.15
linuxlinux>= adfab836f4908deb049a5128082719e689eed964 < 29f0349c5c76b627fe06b87d4b13fa03a6ce8e6429f0349c5c76b627fe06b87d4b13fa03a6ce8e64
linuxlinux>= adfab836f4908deb049a5128082719e689eed964 < 387217b97e99699c34e6d95ce2b91b327fcd853e387217b97e99699c34e6d95ce2b91b327fcd853e
linuxlinux>= adfab836f4908deb049a5128082719e689eed964 < d49c85a1913385eed46dd16a25ad0928253767f0d49c85a1913385eed46dd16a25ad0928253767f0
linuxlinux>= adfab836f4908deb049a5128082719e689eed964 < 30187be29052bba9203b0ae2bdd815e0bc2faaab30187be29052bba9203b0ae2bdd815e0bc2faaab
linuxlinux>= adfab836f4908deb049a5128082719e689eed964 < 5dbe1ebd56470d03b78fc31491a9e4d433106ef25dbe1ebd56470d03b78fc31491a9e4d433106ef2
linuxlinux>= adfab836f4908deb049a5128082719e689eed964 < 49178d4d61e78aed8c837dfeea8a450700f196e249178d4d61e78aed8c837dfeea8a450700f196e2
linuxlinux>= adfab836f4908deb049a5128082719e689eed964 < 7717fc1a12f88701573f9ed897cc4f6699c661e37717fc1a12f88701573f9ed897cc4f6699c661e3
linuxlinux_kernel< 4.14.3064.14.306
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 4.15 < 4.19.2734.19.273
linuxlinux_kernel>= 4.20 < 5.4.2325.4.232
linuxlinux_kernel>= 5.11 < 5.15.935.15.93
linuxlinux_kernel>= 5.16 < 6.1.116.1.11
linuxlinux_kernel>= 5.5 < 5.10.1685.10.168

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.