cbcvebase.
CVE-2023-54322
published 2025-12-30

CVE-2023-54322: In the Linux kernel, the following vulnerability has been resolved: arm64: set __exception_irq_entry with __irq_entry as a default filter_irq_stacks() is…

PriorityP421low3.3
EPSS
0.16%
5.9th percentile
In the Linux kernel, the following vulnerability has been resolved: arm64: set __exception_irq_entry with __irq_entry as a default filter_irq_stacks() is supposed to cut entries which are related irq entries from its call stack. And in_irqentry_text() which is called by filter_irq_stacks() uses __irqentry_text_start/end symbol to find irq entries in callstack. But it doesn't work correctly as without "CONFIG_FUNCTION_GRAPH_TRACER", arm64 kernel doesn't include gic_handle_irq which is entry point of arm64 irq between __irqentry_text_start and __irqentry_text_end as we discussed in below link. https://lore.kernel.org/all/CACT4Y+aReMGLYua2rCLHgFpS9io5cZC04Q8GLs-uNmrn1ezxYQ@mail.gmail.com/#t This problem can makes unintentional deep call stack entries especially in KASAN enabled situation as below. [ 2479.383395]I[0:launcher-loader: 1719] Stack depot reached limit capacity [ 2479.383538]I[0:launcher-loader: 1719] WARNING: CPU: 0 PID: 1719 at lib/stackdepot.c:129 __stack_depot_save+0x464/0x46c [ 2479.385693]I[0:launcher-loader: 1719] pstate: 624000c5 (nZCv daIF +PAN -UAO +TCO -DIT -SSBS BTYPE=--) [ 2479.385724]I[0:launcher-loader: 1719] pc : __stack_depot_save+0x464/0x46c [ 2479.385751]I[0:launcher-loader: 1719] lr : __stack_depot_save+0x460/0x46c [ 2479.385774]I[0:launcher-loader: 1719] sp : ffffffc0080073c0 [ 2479.385793]I[0:launcher-loader: 1719] x29: ffffffc0080073e0 x28: ffffffd00b78a000 x27: 0000000000000000 [ 2479.385839]I[0:launcher-loader: 1719] x26: 000000000004d1dd x25: ffffff891474f000 x24: 00000000ca64d1dd [ 2479.385882]I[0:launcher-loader: 1719] x23: 0000000000000200 x22: 0000000000000220 x21: 0000000000000040 [ 2479.385925]I[0:launcher-loader: 1719] x20: ffffffc008007440 x19: 0000000000000000 x18: 0000000000000000 [ 2479.385969]I[0:launcher-loader: 1719] x17: 2065726568207475 x16: 000000000000005e x15: 2d2d2d2d2d2d2d20 [ 2479.386013]I[0:launcher-loader: 1719] x14: 5d39313731203a72 x13: 00000000002f6b30 x12: 00000000002f6af8 [ 2479.386057]I[0:launcher-

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.191-1 (bullseye)linux 5.10.191-1 (bullseye)
linuxlinux
linuxlinux>= 9a5ad7d0e3e1c6c0c11df89fbc5376f8aaf7a90f < c71d6934c6ac40a97146a410e0320768c7b1bb3cc71d6934c6ac40a97146a410e0320768c7b1bb3c
linuxlinux>= 9a5ad7d0e3e1c6c0c11df89fbc5376f8aaf7a90f < 0bd309f22663f3ee749bea0b6d70642c31a1c0a50bd309f22663f3ee749bea0b6d70642c31a1c0a5
linuxlinux>= 9a5ad7d0e3e1c6c0c11df89fbc5376f8aaf7a90f < 47d74b54180b6b296b489b7895011c9a28979ff147d74b54180b6b296b489b7895011c9a28979ff1
linuxlinux>= 9a5ad7d0e3e1c6c0c11df89fbc5376f8aaf7a90f < d3b219e504fc5c5a25fa7c04c8589ff34baef9a8d3b219e504fc5c5a25fa7c04c8589ff34baef9a8
linuxlinux>= 9a5ad7d0e3e1c6c0c11df89fbc5376f8aaf7a90f < f6794950f0e5ba37e3bbedda4d6ab0aad7395dd3f6794950f0e5ba37e3bbedda4d6ab0aad7395dd3
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 4.3.0 < 5.10.1885.10.188
linuxlinux_kernel>= 5.11.0 < 5.15.1505.15.150
linuxlinux_kernel>= 5.16.0 < 6.4.76.4.7
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.