cbcvebase.
CVE-2023-53090
published 2025-05-02

CVE-2023-53090: In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix an illegal memory access In the kfd_wait_on_events() function, the…

PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.19%
9.4th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix an illegal memory access In the kfd_wait_on_events() function, the kfd_event_waiter structure is allocated by alloc_event_waiters(), but the event field of the waiter structure is not initialized; When copy_from_user() fails in the kfd_wait_on_events() function, it will enter exception handling to release the previously allocated memory of the waiter structure; Due to the event field of the waiters structure being accessed in the free_waiters() function, this results in illegal memory access and system crash, here is the crash log: localhost kernel: RIP: 0010:native_queued_spin_lock_slowpath+0x185/0x1e0 localhost kernel: RSP: 0018:ffffaa53c362bd60 EFLAGS: 00010082 localhost kernel: RAX: ff3d3d6bff4007cb RBX: 0000000000000282 RCX: 00000000002c0000 localhost kernel: RDX: ffff9e855eeacb80 RSI: 000000000000279c RDI: ffffe7088f6a21d0 localhost kernel: RBP: ffffe7088f6a21d0 R08: 00000000002c0000 R09: ffffaa53c362be64 localhost kernel: R10: ffffaa53c362bbd8 R11: 0000000000000001 R12: 0000000000000002 localhost kernel: R13: ffff9e7ead15d600 R14: 0000000000000000 R15: ffff9e7ead15d698 localhost kernel: FS: 0000152a3d111700(0000) GS:ffff9e855ee80000(0000) knlGS:0000000000000000 localhost kernel: CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 localhost kernel: CR2: 0000152938000010 CR3: 000000044d7a4000 CR4: 00000000003506e0 localhost kernel: Call Trace: localhost kernel: _raw_spin_lock_irqsave+0x30/0x40 localhost kernel: remove_wait_queue+0x12/0x50 localhost kernel: kfd_wait_on_events+0x1b6/0x490 [hydcu] localhost kernel: ? ftrace_graph_caller+0xa0/0xa0 localhost kernel: kfd_ioctl+0x38c/0x4a0 [hydcu] localhost kernel: ? kfd_ioctl_set_trap_handler+0x70/0x70 [hydcu] localhost kernel: ? kfd_ioctl_create_queue+0x5a0/0x5a0 [hydcu] localhost kernel: ? ftrace_graph_caller+0xa0/0xa0 localhost kernel: __x64_sys_ioctl+0x8e/0xd0 localhost kernel: ? syscall_trace_enter.isra.18+0x143/0x1b0 localhost k

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.25-1 (bookworm)linux 6.1.25-1 (bookworm)
linuxlinux
linuxlinux>= 4a488a7ad71401169cecee75dc94bcce642e2c53 < 5a3fb3b745af0ce46ec2e0c8e507bae45b9373345a3fb3b745af0ce46ec2e0c8e507bae45b937334
linuxlinux>= 4a488a7ad71401169cecee75dc94bcce642e2c53 < bbf5eada4334a96e3a204b2307ff5b14dc380b0bbbf5eada4334a96e3a204b2307ff5b14dc380b0b
linuxlinux>= 4a488a7ad71401169cecee75dc94bcce642e2c53 < 6936525142a015e854d0a23e9ad9ea0a28b3843d6936525142a015e854d0a23e9ad9ea0a28b3843d
linuxlinux>= 4a488a7ad71401169cecee75dc94bcce642e2c53 < 2fece63b55c5d74cd6f5de51159e2cde37e105552fece63b55c5d74cd6f5de51159e2cde37e10555
linuxlinux>= 4a488a7ad71401169cecee75dc94bcce642e2c53 < d9923e7214a870b312bf61f6a89c7554d0966985d9923e7214a870b312bf61f6a89c7554d0966985
linuxlinux>= 4a488a7ad71401169cecee75dc94bcce642e2c53 < 61f306f8df0d5559659c5578cf6d95236bcdcb2561f306f8df0d5559659c5578cf6d95236bcdcb25
linuxlinux>= 4a488a7ad71401169cecee75dc94bcce642e2c53 < 4fc8fff378b2f2039f2a666d9f8c570f4e58352c4fc8fff378b2f2039f2a666d9f8c570f4e58352c
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 3.19 < 4.19.2794.19.279
linuxlinux_kernel>= 4.20 < 5.4.2385.4.238
linuxlinux_kernel>= 5.11 < 5.15.1045.15.104
linuxlinux_kernel>= 5.16 < 6.1.216.1.21
linuxlinux_kernel>= 5.5 < 5.10.1765.10.176
linuxlinux_kernel>= 6.2 < 6.2.86.2.8

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.