cbcvebase.
CVE-2023-52973
published 2025-03-27

CVE-2023-52973: In the Linux kernel, the following vulnerability has been resolved: vc_screen: move load of struct vc_data pointer in vcs_read() to avoid UAF After a call to…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
20.4th percentile
In the Linux kernel, the following vulnerability has been resolved: vc_screen: move load of struct vc_data pointer in vcs_read() to avoid UAF After a call to console_unlock() in vcs_read() the vc_data struct can be freed by vc_deallocate(). Because of that, the struct vc_data pointer load must be done at the top of while loop in vcs_read() to avoid a UAF when vcs_size() is called. Syzkaller reported a UAF in vcs_size(). BUG: KASAN: use-after-free in vcs_size (drivers/tty/vt/vc_screen.c:215) Read of size 4 at addr ffff8881137479a8 by task 4a005ed81e27e65/1537 CPU: 0 PID: 1537 Comm: 4a005ed81e27e65 Not tainted 6.2.0-rc5 #1 Hardware name: Red Hat KVM, BIOS 1.15.0-2.module Call Trace: __asan_report_load4_noabort (mm/kasan/report_generic.c:350) vcs_size (drivers/tty/vt/vc_screen.c:215) vcs_read (drivers/tty/vt/vc_screen.c:415) vfs_read (fs/read_write.c:468 fs/read_write.c:450) ... Allocated by task 1191: ... kmalloc_trace (mm/slab_common.c:1069) vc_allocate (./include/linux/slab.h:580 ./include/linux/slab.h:720 drivers/tty/vt/vt.c:1128 drivers/tty/vt/vt.c:1108) con_install (drivers/tty/vt/vt.c:3383) tty_init_dev (drivers/tty/tty_io.c:1301 drivers/tty/tty_io.c:1413 drivers/tty/tty_io.c:1390) tty_open (drivers/tty/tty_io.c:2080 drivers/tty/tty_io.c:2126) chrdev_open (fs/char_dev.c:415) do_dentry_open (fs/open.c:883) vfs_open (fs/open.c:1014) ... Freed by task 1548: ... kfree (mm/slab_common.c:1021) vc_port_destruct (drivers/tty/vt/vt.c:1094) tty_port_destructor (drivers/tty/tty_port.c:296) tty_port_put (drivers/tty/tty_port.c:312) vt_disallocate_all (drivers/tty/vt/vt_ioctl.c:662 (discriminator 2)) vt_ioctl (drivers/tty/vt/vt_ioctl.c:903) tty_ioctl (drivers/tty/tty_io.c:2776) ... The buggy address belongs to the object at ffff888113747800 which belongs to the cache kmalloc-1k of size 1024 The buggy address is located 424 bytes inside of 1024-byte region [ffff888113747800, ffff888113747c00) The buggy address belongs to the physical page: page:00000000b3fe6c7c ref

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.11-1 (bookworm)linux 6.1.11-1 (bookworm)
linuxlinux
linuxlinux>= ac751efa6a0d70f2c9daef5c7e3a92270f5c2dff < af79ea9a2443016f64d8fd8d72020cc874f0e066af79ea9a2443016f64d8fd8d72020cc874f0e066
linuxlinux>= ac751efa6a0d70f2c9daef5c7e3a92270f5c2dff < 6332f52f44b9776568bf3c0b714ddfb0bb175e786332f52f44b9776568bf3c0b714ddfb0bb175e78
linuxlinux>= ac751efa6a0d70f2c9daef5c7e3a92270f5c2dff < d0332cbf53dad06a22189cc341391237f4ea6d9fd0332cbf53dad06a22189cc341391237f4ea6d9f
linuxlinux>= ac751efa6a0d70f2c9daef5c7e3a92270f5c2dff < 55515d7d8743b71b80bfe68e89eb9d92630626ab55515d7d8743b71b80bfe68e89eb9d92630626ab
linuxlinux>= ac751efa6a0d70f2c9daef5c7e3a92270f5c2dff < fc9e27f3ba083534b8bbf72ab0f5c810ffdc7d18fc9e27f3ba083534b8bbf72ab0f5c810ffdc7d18
linuxlinux>= ac751efa6a0d70f2c9daef5c7e3a92270f5c2dff < 8506f16aae9daf354e3732bcfd447e2a97f023df8506f16aae9daf354e3732bcfd447e2a97f023df
linuxlinux>= ac751efa6a0d70f2c9daef5c7e3a92270f5c2dff < 226fae124b2dac217ea5436060d623ff3385bc34226fae124b2dac217ea5436060d623ff3385bc34
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 2.6.38 < 4.14.3294.14.329
linuxlinux_kernel>= 4.15 < 4.19.2734.19.273
linuxlinux_kernel>= 4.20 < 5.4.2325.4.232
linuxlinux_kernel>= 5.11 < 5.15.935.15.93
linuxlinux_kernel>= 5.16 < 6.1.116.1.11
linuxlinux_kernel>= 5.5 < 5.10.1685.10.168

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.