CVE-2023-53205
published 2025-09-15CVE-2023-53205: In the Linux kernel, the following vulnerability has been resolved: KVM: s390/diag: fix racy access of physical cpu number in diag 9c handler We do check for…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.15%
5.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
KVM: s390/diag: fix racy access of physical cpu number in diag 9c handler
We do check for target CPU == -1, but this might change at the time we
are going to use it. Hold the physical target CPU in a local variable to
avoid out-of-bound accesses to the cpu arrays.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.52-1 (bookworm) | linux 6.1.52-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 87e28a15c42cc592009c32a8c20e5789059027c2 < a9ccf140a2a03a0ae82be4bdfbdd17bdaea72ff5 | a9ccf140a2a03a0ae82be4bdfbdd17bdaea72ff5 |
| linux | linux | >= 87e28a15c42cc592009c32a8c20e5789059027c2 < 86bfb18bad60fc468e5f112cbbd918462a8dd435 | 86bfb18bad60fc468e5f112cbbd918462a8dd435 |
| linux | linux | >= 87e28a15c42cc592009c32a8c20e5789059027c2 < dc7e0192c470a53d847c79a2796f9ac429477a26 | dc7e0192c470a53d847c79a2796f9ac429477a26 |
| linux | linux | >= 87e28a15c42cc592009c32a8c20e5789059027c2 < 0bc380beb78aa352eadbc21d934dd9606fcee808 | 0bc380beb78aa352eadbc21d934dd9606fcee808 |
| linux | linux_kernel | >= 0 < 6.1.52-1 | 6.1.52-1 |
| linux | linux_kernel | >= 0 < 6.4.4-1 | 6.4.4-1 |
| linux | linux_kernel | >= 0 < 6.4.4-1 | 6.4.4-1 |
| linux | linux_kernel | >= 5.13 < 5.15.121 | 5.15.121 |
| linux | linux_kernel | >= 5.16 < 6.1.39 | 6.1.39 |
| linux | linux_kernel | >= 6.2 < 6.4.4 | 6.4.4 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-53205: In the Linux kernel, the following vulnerability has been resolved: KVM: s390/diag: fix racy access of physical cpu number in diag 9c handler We do ch
osv·2025-09-15·CVSS 7.8
CVE-2023-53205 [HIGH] CVE-2023-53205: In the Linux kernel, the following vulnerability has been resolved: KVM: s390/diag: fix racy access of physical cpu number in diag 9c handler We do ch
In the Linux kernel, the following vulnerability has been resolved: KVM: s390/diag: fix racy access of physical cpu number in diag 9c handler We do check for target CPU == -1, but this might change at the time we are going to use it. Hold the physical target CPU in a local variable to avoid out-of-bound accesses to the cpu arrays.
GHSA
GHSA-9r2v-25mx-g9gj: In the Linux kernel, the following vulnerability has been resolved:
KVM: s390/diag: fix racy access of physical cpu number in diag 9c handler
We do
ghsa_unreviewed·2025-09-15
CVE-2023-53205 [HIGH] CWE-787 GHSA-9r2v-25mx-g9gj: In the Linux kernel, the following vulnerability has been resolved:
KVM: s390/diag: fix racy access of physical cpu number in diag 9c handler
We do
In the Linux kernel, the following vulnerability has been resolved:
KVM: s390/diag: fix racy access of physical cpu number in diag 9c handler
We do check for target CPU == -1, but this might change at the time we
are going to use it. Hold the physical target CPU in a local variable to
avoid out-of-bound accesses to the cpu arrays.
Red Hat
kernel: KVM: s390/diag: fix racy access of physical cpu number in diag 9c handler
vendor_redhat·2025-09-15·CVSS 7.8
CVE-2023-53205 [HIGH] CWE-367 kernel: KVM: s390/diag: fix racy access of physical cpu number in diag 9c handler
kernel: KVM: s390/diag: fix racy access of physical cpu number in diag 9c handler
In the Linux kernel, the following vulnerability has been resolved:
KVM: s390/diag: fix racy access of physical cpu number in diag 9c handler
We do check for target CPU == -1, but this might change at the time we
are going to use it. Hold the physical target CPU in a local variable to
avoid out-of-bound accesses to the cpu arrays.
Statement: This vulnerability is rated Moderate for Red Hat Enterprise Linux on the s390x architecture. The flaw is a race condition in the KVM s390/diag handler that could lead to out-of-bounds access. Triggering this vulnerability requires precise timing and repeated invocations and will most likely result in a denial-of-service. Confidentiality is not impacted as the bug does n
Debian
CVE-2023-53205: linux - In the Linux kernel, the following vulnerability has been resolved: KVM: s390/d...
vendor_debian·2023·CVSS 7.8
CVE-2023-53205 [HIGH] CVE-2023-53205: linux - In the Linux kernel, the following vulnerability has been resolved: KVM: s390/d...
In the Linux kernel, the following vulnerability has been resolved: KVM: s390/diag: fix racy access of physical cpu number in diag 9c handler We do check for target CPU == -1, but this might change at the time we are going to use it. Hold the physical target CPU in a local variable to avoid out-of-bound accesses to the cpu arrays.
Scope: local
bookworm: resolved (fixed in 6.1.52-1)
bullseye: resolved
forky: resolved (fixed in 6.4.4-1)
sid: resolved (fixed in 6.4.4-1)
trixie: resolved (fixed in 6.4.4-1)
No detection rules found.
No public exploits indexed.
2025-09-15
Published