cbcvebase.
CVE-2023-54232
published 2025-12-30

CVE-2023-54232: In the Linux kernel, the following vulnerability has been resolved: m68k: Only force 030 bus error if PC not in exception table __get_kernel_nofault() does…

PriorityP421
EPSS
0.18%
8.2th percentile
In the Linux kernel, the following vulnerability has been resolved: m68k: Only force 030 bus error if PC not in exception table __get_kernel_nofault() does copy data in supervisor mode when forcing a task backtrace log through /proc/sysrq_trigger. This is expected cause a bus error exception on e.g. NULL pointer dereferencing when logging a kernel task has no workqueue associated. This bus error ought to be ignored. Our 030 bus error handler is ill equipped to deal with this: Whenever ssw indicates a kernel mode access on a data fault, we don't even attempt to handle the fault and instead always send a SEGV signal (or panic). As a result, the check for exception handling at the fault PC (buried in send_sig_fault() which gets called from do_page_fault() eventually) is never used. In contrast, both 040 and 060 access error handlers do not care whether a fault happened on supervisor mode access, and will call do_page_fault() on those, ultimately honoring the exception table. Add a check in bus_error030 to call do_page_fault() in case we do have an entry for the fault PC in our exception table. I had attempted a fix for this earlier in 2019 that did rely on testing pagefault_disabled() (see link below) to achieve the same thing, but this patch should be more generic. Tested on 030 Atari Falcon.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.25-1 (bookworm)linux 6.1.25-1 (bookworm)
linuxlinux
linuxlinux>= f2325ecebc5b7988fd49968bd3a660fd1594dc84 < 1a6059f5ed57f48edfe7159404ff7d538d9d405b1a6059f5ed57f48edfe7159404ff7d538d9d405b
linuxlinux>= f2325ecebc5b7988fd49968bd3a660fd1594dc84 < f55cb52ec98b22125f5bda36391edb8894f7e8cff55cb52ec98b22125f5bda36391edb8894f7e8cf
linuxlinux>= f2325ecebc5b7988fd49968bd3a660fd1594dc84 < 2100e374251a8fc00cce1916cfc50f3cb652cbe32100e374251a8fc00cce1916cfc50f3cb652cbe3
linuxlinux>= f2325ecebc5b7988fd49968bd3a660fd1594dc84 < df1da53a7e98f0b2a0eb2241c154f148f2f2c1d8df1da53a7e98f0b2a0eb2241c154f148f2f2c1d8
linuxlinux>= f2325ecebc5b7988fd49968bd3a660fd1594dc84 < 8bf8d5dade4c5e1d8a2386f29253ed28b5d877358bf8d5dade4c5e1d8a2386f29253ed28b5d87735
linuxlinux>= f2325ecebc5b7988fd49968bd3a660fd1594dc84 < 54fa25ffab2b700df5abd58c136d64a912c5395354fa25ffab2b700df5abd58c136d64a912c53953
linuxlinux>= f2325ecebc5b7988fd49968bd3a660fd1594dc84 < ec15405b80fc15ffc87a23d01378ae061c1aba07ec15405b80fc15ffc87a23d01378ae061c1aba07
linuxlinux>= f2325ecebc5b7988fd49968bd3a660fd1594dc84 < e36a82bebbf7da814530d5a179bef9df5934b717e36a82bebbf7da814530d5a179bef9df5934b717
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 2.6.18 < 4.14.3124.14.312
linuxlinux_kernel>= 4.15.0 < 4.19.2804.19.280
linuxlinux_kernel>= 4.20.0 < 5.4.2405.4.240
linuxlinux_kernel>= 5.11.0 < 5.15.1055.15.105
linuxlinux_kernel>= 5.16.0 < 6.1.226.1.22
linuxlinux_kernel>= 5.5.0 < 5.10.1775.10.177
linuxlinux_kernel>= 6.2.0 < 6.2.96.2.9
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.