cbcvebase.
CVE-2023-54113
published 2025-12-24

CVE-2023-54113: In the Linux kernel, the following vulnerability has been resolved: rcu: dump vmalloc memory info safely Currently, for double invoke call_rcu(), will dump…

PriorityP420medium4.5
EPSS
0.17%
7.1th percentile
In the Linux kernel, the following vulnerability has been resolved: rcu: dump vmalloc memory info safely Currently, for double invoke call_rcu(), will dump rcu_head objects memory info, if the objects is not allocated from the slab allocator, the vmalloc_dump_obj() will be invoke and the vmap_area_lock spinlock need to be held, since the call_rcu() can be invoked in interrupt context, therefore, there is a possibility of spinlock deadlock scenarios. And in Preempt-RT kernel, the rcutorture test also trigger the following lockdep warning: BUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:48 in_atomic(): 1, irqs_disabled(): 1, non_block: 0, pid: 1, name: swapper/0 preempt_count: 1, expected: 0 RCU nest depth: 1, expected: 1 3 locks held by swapper/0/1: #0: ffffffffb534ee80 (fullstop_mutex){+.+.}-{4:4}, at: torture_init_begin+0x24/0xa0 #1: ffffffffb5307940 (rcu_read_lock){....}-{1:3}, at: rcu_torture_init+0x1ec7/0x2370 #2: ffffffffb536af40 (vmap_area_lock){+.+.}-{3:3}, at: find_vmap_area+0x1f/0x70 irq event stamp: 565512 hardirqs last enabled at (565511): [] __call_rcu_common+0x218/0x940 hardirqs last disabled at (565512): [] rcu_torture_init+0x20b2/0x2370 softirqs last enabled at (399112): [] __local_bh_enable_ip+0x126/0x170 softirqs last disabled at (399106): [] inet_register_protosw+0x9/0x1d0 Preemption disabled at: [] rcu_torture_init+0x1f13/0x2370 CPU: 0 PID: 1 Comm: swapper/0 Tainted: G W 6.5.0-rc4-rt2-yocto-preempt-rt+ #15 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.2-0-gea1b7a073390-prebuilt.qemu.org 04/01/2014 Call Trace: dump_stack_lvl+0x68/0xb0 dump_stack+0x14/0x20 __might_resched+0x1aa/0x280 ? __pfx_rcu_torture_err_cb+0x10/0x10 rt_spin_lock+0x53/0x130 ? find_vmap_area+0x1f/0x70 find_vmap_area+0x1f/0x70 vmalloc_dump_obj+0x20/0x60 mem_dump_obj+0x22/0x90 __call_rcu_common+0x5bf/0x940 ? debug_smp_processor_id+0x1b/0x30 call_rcu_hurry+0x14/0x20 rcu_torture_init+0x1f82/0x2370 ? __pfx_rcu_torture_leak_cb+

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.55-1 (bookworm)linux 6.1.55-1 (bookworm)
linuxlinux
linuxlinux>= 98f180837a896ecedf8f7e12af22b57f271d43c9 < 0a22f9c17b1aa2a35b5eedee928f7841595b55cd0a22f9c17b1aa2a35b5eedee928f7841595b55cd
linuxlinux>= 98f180837a896ecedf8f7e12af22b57f271d43c9 < 3f7a4e88e40e38c0b16a4bcb599b7b1d8c81440d3f7a4e88e40e38c0b16a4bcb599b7b1d8c81440d
linuxlinux>= 98f180837a896ecedf8f7e12af22b57f271d43c9 < dddca4c46ec92f83449bc91dd199f46a89e066bedddca4c46ec92f83449bc91dd199f46a89e066be
linuxlinux>= 98f180837a896ecedf8f7e12af22b57f271d43c9 < 8fb1601ec0a2c4c34fc2170af767e5c2a64005738fb1601ec0a2c4c34fc2170af767e5c2a6400573
linuxlinux>= 98f180837a896ecedf8f7e12af22b57f271d43c9 < c83ad36a18c02c0f51280b50272327807916987fc83ad36a18c02c0f51280b50272327807916987f
linuxlinux_kernel>= 0 < 6.1.55-16.1.55-1
linuxlinux_kernel>= 0 < 6.5.3-16.5.3-1
linuxlinux_kernel>= 0 < 6.5.3-16.5.3-1
linuxlinux_kernel>= 5.12.0 < 5.15.1325.15.132
linuxlinux_kernel>= 5.16.0 < 6.1.536.1.53
linuxlinux_kernel>= 6.2.0 < 6.4.166.4.16
linuxlinux_kernel>= 6.5.0 < 6.5.36.5.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.