CVE & CISA-KEV Catalog

CVE-2023-52587

MEDIUM
5.5
CVSS v3
NVD

Description

In the Linux kernel, the following vulnerability has been resolved: IB/ipoib: Fix mcast list locking Releasing the `priv->lock` while iterating the `priv->multicast_list` in `ipoib_mcast_join_task()` opens a window for `ipoib_mcast_dev_flush()` to remove the items while in the middle of iteration. If the mcast is removed while the lock was dropped, the for loop spins forever resulting in a hard lockup (as was reported on RHEL 4.18.0-372.75.1.el8_6 kernel): Task A (kworker/u72:2 below) | Task B (kworker/u72:0 below) -----------------------------------+----------------------------------- ipoib_mcast_join_task(work) | ipoib_ib_dev_flush_light(work) spin_lock_irq(&priv->lock) | __ipoib_ib_dev_flush(priv, ...) list_for_each_entry(mcast, | ipoib_mcast_dev_flush(dev = priv->dev) &priv->multicast_list, list) | ipoib_mcast_join(dev, mcast) | spin_unlock_irq(&priv->lock) | | spin_lock_irqsave(&priv->lock, flags) | list_for_each_entry_safe(mcast, tmcast, | &priv->multicast_list, list) | list_del(&mcast->list); | list_add_tail(&mcast->list, &remove_list) | spin_unlock_irqrestore(&priv->lock, flags) spin_lock_irq(&priv->lock) | | ipoib_mcast_remove_list(&remove_list) (Here, `mcast` is no longer on the | list_for_each_entry_safe(mcast, tmcast, `priv->multicast_list` and we keep | remove_list, list) spinning on the `remove_list` of | >>> wait_for_completion(&mcast->done) the other thread which is blocked | and the list is still valid on | it's stack.) Fix this by keeping the lock held and changing to GFP_ATOMIC to prevent eventual sleeps. Unfortunately we could not reproduce the lockup and confirm this fix but based on the code review I think this fix should address such lockups. crash> bc 31 PID: 747 TASK: ff1c6a1a007e8000 CPU: 31 COMMAND: "kworker/u72:2" -- [exception RIP: ipoib_mcast_join_task+0x1b1] RIP: ffffffffc0944ac1 RSP: ff646f199a8c7e00 RFLAGS: 00000002 RAX: 0000000000000000 RBX: ff1c6a1a04dc82f8 RCX: 0000000000000000 work (&priv->mcast_task{,.work}) RDX: ff1c6a192d60ac68 RSI: 0000000000000286 RDI: ff1c6a1a04dc8000 &mcast->list RBP: ff646f199a8c7e90 R8: ff1c699980019420 R9: ff1c6a1920c9a000 R10: ff646f199a8c7e00 R11: ff1c6a191a7d9800 R12: ff1c6a192d60ac00 mcast R13: ff1c6a1d82200000 R14: ff1c6a1a04dc8000 R15: ff1c6a1a04dc82d8 dev priv (&priv->lock) &priv->multicast_list (aka head) ORIG_RAX: ffffffffffffffff CS: 0010 SS: 0018 --- <NMI exception stack> --- #5 [ff646f199a8c7e00] ipoib_mcast_join_task+0x1b1 at ffffffffc0944ac1 [ib_ipoib] #6 [ff646f199a8c7e98] process_one_work+0x1a7 at ffffffff9bf10967 crash> rx ff646f199a8c7e68 ff646f199a8c7e68: ff1c6a1a04dc82f8 <<< work = &priv->mcast_task.work crash> list -hO ipoib_dev_priv.multicast_list ff1c6a1a04dc8000 (empty) crash> ipoib_dev_priv.mcast_task.work.func,mcast_mutex.owner.counter ff1c6a1a04dc8000 mcast_task.work.func = 0xffffffffc0944910 <ipoib_mcast_join_task>, mcast_mutex.owner.counter = 0xff1c69998efec000 crash> b 8 PID: 8 TASK: ff1c69998efec000 CPU: 33 COMMAND: "kworker/u72:0" -- #3 [ff646f1980153d50] wait_for_completion+0x96 at ffffffff9c7d7646 #4 [ff646f1980153d90] ipoib_mcast_remove_list+0x56 at ffffffffc0944dc6 [ib_ipoib] #5 [ff646f1980153de8] ipoib_mcast_dev_flush+0x1a7 at ffffffffc09455a7 [ib_ipoib] #6 [ff646f1980153e58] __ipoib_ib_dev_flush+0x1a4 at ffffffffc09431a4 [ib_ipoib] #7 [ff ---truncated---

How to fix

Remediation Available
linuxDebian
Fixed in:5.10.216-1CVE-2023-52587
Fixed in:6.1.82-1CVE-2023-52587
Fixed in:6.7.7-1CVE-2023-52587
Fixed in:6.7.7-1CVE-2023-52587
linuxUbuntu
Fixed in:5.4.0-181.201USN-6767-1
Fixed in:5.15.0-106.116USN-6766-1
Fixed in:6.5.0-41.41USN-6818-1
linux-awsUbuntu
Fixed in:5.4.0-1124.134USN-6767-1
Fixed in:5.15.0-1061.67USN-6766-3
Fixed in:6.5.0-1021.21USN-6819-2
linux-aws-5.15Ubuntu
Fixed in:5.15.0-1061.67~20.04.1USN-6766-3
linux-aws-5.4Ubuntu
Fixed in:5.4.0-1124.134~18.04.1USN-6767-1
linux-azureUbuntu
Fixed in:5.4.0-1129.136USN-6767-1
Fixed in:5.15.0-1063.72USN-6766-1
Fixed in:6.5.0-1022.23USN-6819-1
linux-azure-5.15Ubuntu
Fixed in:5.15.0-1063.72~20.04.1USN-6766-1
linux-azure-5.4Ubuntu
Fixed in:5.4.0-1129.136~18.04.1USN-6767-1
linux-azure-6.5Ubuntu
Fixed in:6.5.0-1022.23~22.04.1USN-6819-1
linux-azure-fdeUbuntu
Fixed in:5.15.0-1063.72.1USN-6766-1
linux-azure-fde-5.15Ubuntu
Fixed in:5.15.0-1063.72~20.04.1.1USN-6766-1
linux-bluefieldUbuntu
Fixed in:5.4.0-1084.91USN-6767-2
linux-gcpUbuntu
Fixed in:5.4.0-1128.137USN-6767-1
Fixed in:5.15.0-1059.67USN-6766-1
Fixed in:6.5.0-1022.24USN-6818-1
linux-gcp-5.15Ubuntu
Fixed in:5.15.0-1059.67~20.04.1USN-6766-1
linux-gcp-5.4Ubuntu
Fixed in:5.4.0-1128.137~18.04.1USN-6767-1
linux-gcp-6.5Ubuntu
Fixed in:6.5.0-1022.24~22.04.1USN-6818-1
linux-gkeUbuntu
Fixed in:5.15.0-1058.63USN-6766-1
linux-gkeopUbuntu
Fixed in:5.4.0-1091.95USN-6767-1
Fixed in:5.15.0-1044.51USN-6766-1
linux-gkeop-5.15Ubuntu
Fixed in:5.15.0-1044.51~20.04.1USN-6766-1
linux-hwe-5.15Ubuntu
Fixed in:5.15.0-106.116~20.04.1USN-6766-2
linux-hwe-5.4Ubuntu
Fixed in:5.4.0-181.201~18.04.1USN-6767-1
linux-hwe-6.5Ubuntu
Fixed in:6.5.0-41.41~22.04.2USN-6818-4
linux-ibmUbuntu
Fixed in:5.4.0-1071.76USN-6767-1
Fixed in:5.15.0-1054.57USN-6766-1
linux-ibm-5.15Ubuntu
Fixed in:5.15.0-1054.57~20.04.1USN-6766-1
linux-ibm-5.4Ubuntu
Fixed in:5.4.0-1071.76~18.04.1USN-6767-1
linux-image-5.15.0-1044-gkeopUbuntu
Fixed in:5.15.0-1044.51~20.04.1USN-6766-1
Fixed in:5.15.0-1044.51USN-6766-1
linux-image-5.15.0-1054-ibmUbuntu
Fixed in:5.15.0-1054.57~20.04.1USN-6766-1
Fixed in:5.15.0-1054.57USN-6766-1
linux-image-5.15.0-1054-nvidiaUbuntu
Fixed in:5.15.0-1054.55USN-6766-1
linux-image-5.15.0-1054-nvidia-lowlatencyUbuntu
Fixed in:5.15.0-1054.55USN-6766-1
linux-image-5.15.0-1054-raspiUbuntu
Fixed in:5.15.0-1054.57USN-6766-2
linux-image-5.15.0-1057-intel-iotgUbuntu
Fixed in:5.15.0-1057.63USN-6795-1
linux-image-5.15.0-1058-gkeUbuntu
Fixed in:5.15.0-1058.63USN-6766-1
linux-image-5.15.0-1058-intel-iotgUbuntu
Fixed in:5.15.0-1058.64~20.04.1USN-6828-1
linux-image-5.15.0-1058-kvmUbuntu
Fixed in:5.15.0-1058.63USN-6766-1
linux-image-5.15.0-1059-gcpUbuntu
Fixed in:5.15.0-1059.67~20.04.1USN-6766-1
Fixed in:5.15.0-1059.67USN-6766-1
linux-image-5.15.0-1059-oracleUbuntu
Fixed in:5.15.0-1059.65~20.04.1USN-6766-1
Fixed in:5.15.0-1059.65USN-6766-1
linux-image-5.15.0-106-genericUbuntu
Fixed in:5.15.0-106.116~20.04.1USN-6766-2
Fixed in:5.15.0-106.116USN-6766-1
linux-image-5.15.0-106-generic-64kUbuntu
Fixed in:5.15.0-106.116~20.04.1USN-6766-2
Fixed in:5.15.0-106.116USN-6766-1
linux-image-5.15.0-106-generic-lpaeUbuntu
Fixed in:5.15.0-106.116~20.04.1USN-6766-2
Fixed in:5.15.0-106.116USN-6766-1
linux-image-5.15.0-106-lowlatencyUbuntu
Fixed in:5.15.0-106.116~20.04.1USN-6766-1
Fixed in:5.15.0-106.116USN-6766-1
linux-image-5.15.0-106-lowlatency-64kUbuntu
Fixed in:5.15.0-106.116~20.04.1USN-6766-1
Fixed in:5.15.0-106.116USN-6766-1
linux-image-5.15.0-1061-awsUbuntu
Fixed in:5.15.0-1061.67~20.04.1USN-6766-3
Fixed in:5.15.0-1061.67USN-6766-3
linux-image-5.15.0-1063-azureUbuntu
Fixed in:5.15.0-1063.72~20.04.1USN-6766-1
Fixed in:5.15.0-1063.72USN-6766-1
linux-image-5.15.0-1063-azure-fdeUbuntu
Fixed in:5.15.0-1063.72~20.04.1.1USN-6766-1
Fixed in:5.15.0-1063.72.1USN-6766-1
linux-image-5.4.0-1036-iotUbuntu
Fixed in:5.4.0-1036.37USN-6767-1
linux-image-5.4.0-1043-xilinx-zynqmpUbuntu
Fixed in:5.4.0-1043.47USN-6767-1
linux-image-5.4.0-1071-ibmUbuntu
Fixed in:5.4.0-1071.76~18.04.1USN-6767-1
Fixed in:5.4.0-1071.76USN-6767-1
linux-image-5.4.0-1084-bluefieldUbuntu
Fixed in:5.4.0-1084.91USN-6767-2
linux-image-5.4.0-1091-gkeopUbuntu
Fixed in:5.4.0-1091.95USN-6767-1
linux-image-5.4.0-1108-raspiUbuntu
Fixed in:5.4.0-1108.120~18.04.1USN-6767-1
Fixed in:5.4.0-1108.120USN-6767-1
linux-image-5.4.0-1112-kvmUbuntu
Fixed in:5.4.0-1112.119USN-6767-1
linux-image-5.4.0-1123-oracleUbuntu
Fixed in:5.4.0-1123.132~18.04.1USN-6767-1
Fixed in:5.4.0-1123.132USN-6767-1
linux-image-5.4.0-1124-awsUbuntu
Fixed in:5.4.0-1124.134~18.04.1USN-6767-1
Fixed in:5.4.0-1124.134USN-6767-1
linux-image-5.4.0-1128-gcpUbuntu
Fixed in:5.4.0-1128.137~18.04.1USN-6767-1
Fixed in:5.4.0-1128.137USN-6767-1
linux-image-5.4.0-1129-azureUbuntu
Fixed in:5.4.0-1129.136~18.04.1USN-6767-1
Fixed in:5.4.0-1129.136USN-6767-1
linux-image-5.4.0-181-genericUbuntu
Fixed in:5.4.0-181.201~18.04.1USN-6767-1
Fixed in:5.4.0-181.201USN-6767-1
linux-image-5.4.0-181-generic-lpaeUbuntu
Fixed in:5.4.0-181.201USN-6767-1
linux-image-5.4.0-181-lowlatencyUbuntu
Fixed in:5.4.0-181.201~18.04.1USN-6767-1
Fixed in:5.4.0-181.201USN-6767-1
linux-image-6.1.0-1035-oemUbuntu
Fixed in:6.1.0-1035.35USN-6688-1
linux-image-6.5.0-1015-starfiveUbuntu
Fixed in:6.5.0-1015.16~22.04.1USN-6819-1
Fixed in:6.5.0-1015.16USN-6819-1
linux-image-6.5.0-1017-laptopUbuntu
Fixed in:6.5.0-1017.20USN-6818-2
linux-image-6.5.0-1018-raspiUbuntu
Fixed in:6.5.0-1018.21USN-6818-1
linux-image-6.5.0-1021-awsUbuntu
Fixed in:6.5.0-1021.21USN-6819-2
linux-image-6.5.0-1021-nvidiaUbuntu
Fixed in:6.5.0-1021.22USN-6818-3
linux-image-6.5.0-1021-nvidia-64kUbuntu
Fixed in:6.5.0-1021.22USN-6818-3
linux-image-6.5.0-1022-azureUbuntu
Fixed in:6.5.0-1022.23~22.04.1USN-6819-1
Fixed in:6.5.0-1022.23USN-6819-1
linux-image-6.5.0-1022-azure-fdeUbuntu
Fixed in:6.5.0-1022.23~22.04.1USN-6819-1
Fixed in:6.5.0-1022.23USN-6819-1
linux-image-6.5.0-1022-gcpUbuntu
Fixed in:6.5.0-1022.24~22.04.1USN-6818-1
Fixed in:6.5.0-1022.24USN-6818-1
linux-image-6.5.0-1024-oemUbuntu
Fixed in:6.5.0-1024.25USN-6819-3
linux-image-6.5.0-1024-oracleUbuntu
Fixed in:6.5.0-1024.24~22.04.1USN-6819-4
Fixed in:6.5.0-1024.24USN-6819-2
linux-image-6.5.0-1024-oracle-64kUbuntu
Fixed in:6.5.0-1024.24~22.04.1USN-6819-4
Fixed in:6.5.0-1024.24USN-6819-2
linux-image-6.5.0-41-genericUbuntu
Fixed in:6.5.0-41.41~22.04.2USN-6818-4
Fixed in:6.5.0-41.41USN-6818-1
linux-image-6.5.0-41-generic-64kUbuntu
Fixed in:6.5.0-41.41~22.04.2USN-6818-4
Fixed in:6.5.0-41.41USN-6818-1
linux-image-6.5.0-41-lowlatencyUbuntu
Fixed in:6.5.0-41.41.1~22.04.1USN-6818-1
Fixed in:6.5.0-41.41.1USN-6818-1
linux-image-6.5.0-41-lowlatency-64kUbuntu
Fixed in:6.5.0-41.41.1~22.04.1USN-6818-1
Fixed in:6.5.0-41.41.1USN-6818-1
linux-image-awsUbuntu
Fixed in:5.4.0.1124.134~18.04.1USN-6767-1
Fixed in:5.15.0.1061.67~20.04.1USN-6766-3
Fixed in:6.5.0.1021.21USN-6819-2
linux-image-aws-lts-20.04Ubuntu
Fixed in:5.4.0.1124.121USN-6767-1
linux-image-aws-lts-22.04Ubuntu
Fixed in:5.15.0.1061.61USN-6766-3
linux-image-azureUbuntu
Fixed in:5.4.0.1129.136~18.04.1USN-6767-1
Fixed in:5.15.0.1063.72~20.04.1USN-6766-1
Fixed in:6.5.0.1022.23~22.04.1USN-6819-1
Fixed in:6.5.0.1022.26USN-6819-1
linux-image-azure-cvmUbuntu
Fixed in:5.15.0.1063.72~20.04.1USN-6766-1
linux-image-azure-fdeUbuntu
Fixed in:5.15.0.1063.72~20.04.1.41USN-6766-1
Fixed in:6.5.0.1022.23~22.04.1USN-6819-1
Fixed in:6.5.0.1022.26USN-6819-1
linux-image-azure-fde-lts-22.04Ubuntu
Fixed in:5.15.0.1063.72.41USN-6766-1
linux-image-azure-lts-20.04Ubuntu
Fixed in:5.4.0.1129.123USN-6767-1
linux-image-azure-lts-22.04Ubuntu
Fixed in:5.15.0.1063.61USN-6766-1
linux-image-bluefieldUbuntu
Fixed in:5.4.0.1084.80USN-6767-2
linux-image-gcpUbuntu
Fixed in:5.4.0.1128.137~18.04.1USN-6767-1
Fixed in:5.15.0.1059.67~20.04.1USN-6766-1
Fixed in:6.5.0.1022.24~22.04.1USN-6818-1
Fixed in:6.5.0.1022.24USN-6818-1
linux-image-gcp-lts-20.04Ubuntu
Fixed in:5.4.0.1128.130USN-6767-1
linux-image-gcp-lts-22.04Ubuntu
Fixed in:5.15.0.1059.55USN-6766-1
linux-image-genericUbuntu
Fixed in:5.4.0.181.179USN-6767-1
Fixed in:5.15.0.106.106USN-6766-1
Fixed in:6.5.0.41.41USN-6818-1
linux-image-generic-64kUbuntu
Fixed in:5.15.0.106.106USN-6766-1
Fixed in:6.5.0.41.41USN-6818-1
linux-image-generic-64k-hwe-20.04Ubuntu
Fixed in:5.15.0.106.116~20.04.1USN-6766-2
linux-image-generic-64k-hwe-22.04Ubuntu
Fixed in:6.5.0.41.41~22.04.2USN-6818-4
linux-image-generic-hwe-18.04Ubuntu
Fixed in:5.4.0.181.201~18.04.1USN-6767-1
linux-image-generic-hwe-20.04Ubuntu
Fixed in:5.15.0.106.116~20.04.1USN-6766-2
linux-image-generic-hwe-22.04Ubuntu
Fixed in:6.5.0.41.41~22.04.2USN-6818-4
linux-image-generic-lpaeUbuntu
Fixed in:5.4.0.181.179USN-6767-1
Fixed in:5.15.0.106.106USN-6766-1
Fixed in:6.5.0.41.41USN-6818-1
linux-image-generic-lpae-hwe-20.04Ubuntu
Fixed in:5.15.0.106.116~20.04.1USN-6766-2
linux-image-gkeUbuntu
Fixed in:5.15.0.1058.57USN-6766-1
linux-image-gke-5.15Ubuntu
Fixed in:5.15.0.1058.57USN-6766-1
linux-image-gkeopUbuntu
Fixed in:5.4.0.1091.89USN-6767-1
Fixed in:5.15.0.1044.43USN-6766-1
linux-image-gkeop-5.15Ubuntu
Fixed in:5.15.0.1044.51~20.04.1USN-6766-1
Fixed in:5.15.0.1044.43USN-6766-1
linux-image-gkeop-5.4Ubuntu
Fixed in:5.4.0.1091.89USN-6767-1
linux-image-ibmUbuntu
Fixed in:5.4.0.1071.76~18.04.1USN-6767-1
Fixed in:5.15.0.1054.57~20.04.1USN-6766-1
Fixed in:5.15.0.1054.50USN-6766-1
linux-image-ibm-lts-20.04Ubuntu
Fixed in:5.4.0.1071.100USN-6767-1
linux-image-intelUbuntu
Fixed in:5.15.0.1058.64~20.04.1USN-6828-1
linux-image-intel-iotgUbuntu
Fixed in:5.15.0.1058.64~20.04.1USN-6828-1
Fixed in:5.15.0.1057.57USN-6795-1
linux-image-kvmUbuntu
Fixed in:5.4.0.1112.108USN-6767-1
Fixed in:5.15.0.1058.54USN-6766-1
Fixed in:6.5.0.41.41USN-6818-1
linux-image-laptop-23.10Ubuntu
Fixed in:6.5.0.1017.20USN-6818-2
linux-image-lowlatencyUbuntu
Fixed in:5.4.0.181.179USN-6767-1
Fixed in:5.15.0.106.101USN-6766-1
Fixed in:6.5.0.41.41.1USN-6818-1
linux-image-lowlatency-64kUbuntu
Fixed in:5.15.0.106.101USN-6766-1
Fixed in:6.5.0.41.41.1USN-6818-1
linux-image-lowlatency-64k-hwe-20.04Ubuntu
Fixed in:5.15.0.106.116~20.04.1USN-6766-1
linux-image-lowlatency-64k-hwe-22.04Ubuntu
Fixed in:6.5.0.41.41.1~22.04.1USN-6818-1
linux-image-lowlatency-hwe-18.04Ubuntu
Fixed in:5.4.0.181.201~18.04.1USN-6767-1
linux-image-lowlatency-hwe-20.04Ubuntu
Fixed in:5.15.0.106.116~20.04.1USN-6766-1
linux-image-lowlatency-hwe-22.04Ubuntu
Fixed in:6.5.0.41.41.1~22.04.1USN-6818-1
linux-image-nvidiaUbuntu
Fixed in:5.15.0.1054.54USN-6766-1
linux-image-nvidia-6.5Ubuntu
Fixed in:6.5.0.1021.29USN-6818-3
linux-image-nvidia-64k-6.5Ubuntu
Fixed in:6.5.0.1021.29USN-6818-3
linux-image-nvidia-64k-hwe-22.04Ubuntu
Fixed in:6.5.0.1021.29USN-6818-3
linux-image-nvidia-hwe-22.04Ubuntu
Fixed in:6.5.0.1021.29USN-6818-3
linux-image-nvidia-lowlatencyUbuntu
Fixed in:5.15.0.1054.54USN-6766-1
linux-image-oemUbuntu
Fixed in:5.4.0.181.201~18.04.1USN-6767-1
Fixed in:5.4.0.181.179USN-6767-1
linux-image-oem-20.04Ubuntu
Fixed in:5.15.0.106.116~20.04.1USN-6766-2
linux-image-oem-20.04bUbuntu
Fixed in:5.15.0.106.116~20.04.1USN-6766-2
linux-image-oem-20.04cUbuntu
Fixed in:5.15.0.106.116~20.04.1USN-6766-2
linux-image-oem-20.04dUbuntu
Fixed in:5.15.0.106.116~20.04.1USN-6766-2
linux-image-oem-22.04Ubuntu
Fixed in:6.1.0.1035.36USN-6688-1
Fixed in:6.5.0.1024.26USN-6819-3
linux-image-oem-22.04aUbuntu
Fixed in:6.5.0.1024.26USN-6819-3
Fixed in:6.1.0.1035.36USN-6688-1
linux-image-oem-22.04bUbuntu
Fixed in:6.1.0.1035.36USN-6688-1
Fixed in:6.5.0.1024.26USN-6819-3
linux-image-oem-22.04cUbuntu
Fixed in:6.1.0.1035.36USN-6688-1
Fixed in:6.5.0.1024.26USN-6819-3
linux-image-oem-22.04dUbuntu
Fixed in:6.5.0.1024.26USN-6819-3
linux-image-oem-osp1Ubuntu
Fixed in:5.4.0.181.201~18.04.1USN-6767-1
Fixed in:5.4.0.181.179USN-6767-1
linux-image-oracleUbuntu
Fixed in:5.4.0.1123.132~18.04.1USN-6767-1
Fixed in:5.15.0.1059.65~20.04.1USN-6766-1
Fixed in:6.5.0.1024.24~22.04.1USN-6819-4
Fixed in:6.5.0.1024.26USN-6819-2
linux-image-oracle-64kUbuntu
Fixed in:6.5.0.1024.24~22.04.1USN-6819-4
Fixed in:6.5.0.1024.26USN-6819-2
linux-image-oracle-lts-20.04Ubuntu
Fixed in:5.4.0.1123.116USN-6767-1
linux-image-oracle-lts-22.04Ubuntu
Fixed in:5.15.0.1059.55USN-6766-1
linux-image-raspiUbuntu
Fixed in:5.4.0.1108.138USN-6767-1
Fixed in:5.15.0.1054.52USN-6766-2
Fixed in:6.5.0.1018.19USN-6818-1
linux-image-raspi-hwe-18.04Ubuntu
Fixed in:5.4.0.1108.120~18.04.1USN-6767-1
linux-image-raspi-nolpaeUbuntu
Fixed in:5.15.0.1054.52USN-6766-2
Fixed in:6.5.0.1018.19USN-6818-1
linux-image-raspi2Ubuntu
Fixed in:5.4.0.1108.138USN-6767-1
linux-image-snapdragon-hwe-18.04Ubuntu
Fixed in:5.4.0.181.201~18.04.1USN-6767-1
linux-image-starfiveUbuntu
Fixed in:6.5.0.1015.16~22.04.1USN-6819-1
Fixed in:6.5.0.1015.17USN-6819-1
linux-image-virtualUbuntu
Fixed in:5.4.0.181.179USN-6767-1
Fixed in:5.15.0.106.106USN-6766-1
Fixed in:6.5.0.41.41USN-6818-1
linux-image-virtual-hwe-18.04Ubuntu
Fixed in:5.4.0.181.201~18.04.1USN-6767-1
linux-image-virtual-hwe-20.04Ubuntu
Fixed in:5.15.0.106.116~20.04.1USN-6766-2
linux-image-virtual-hwe-22.04Ubuntu
Fixed in:6.5.0.41.41~22.04.2USN-6818-4
linux-image-xilinx-zynqmpUbuntu
Fixed in:5.4.0.1043.43USN-6767-1
linux-intel-iotgUbuntu
Fixed in:5.15.0-1057.63USN-6795-1
linux-intel-iotg-5.15Ubuntu
Fixed in:5.15.0-1058.64~20.04.1USN-6828-1
linux-iotUbuntu
Fixed in:5.4.0-1036.37USN-6767-1
linux-kvmUbuntu
Fixed in:5.4.0-1112.119USN-6767-1
Fixed in:5.15.0-1058.63USN-6766-1
linux-laptopUbuntu
Fixed in:6.5.0-1017.20USN-6818-2
linux-lowlatencyUbuntu
Fixed in:5.15.0-106.116USN-6766-1
Fixed in:6.5.0-41.41.1USN-6818-1
linux-lowlatency-hwe-5.15Ubuntu
Fixed in:5.15.0-106.116~20.04.1USN-6766-1
linux-lowlatency-hwe-6.5Ubuntu
Fixed in:6.5.0-41.41.1~22.04.1USN-6818-1
linux-nvidiaUbuntu
Fixed in:5.15.0-1054.55USN-6766-1
linux-nvidia-6.5Ubuntu
Fixed in:6.5.0-1021.22USN-6818-3
linux-oem-6.1Ubuntu
Fixed in:6.1.0-1035.35USN-6688-1
linux-oem-6.5Ubuntu
Fixed in:6.5.0-1024.25USN-6819-3
linux-oracleUbuntu
Fixed in:5.4.0-1123.132USN-6767-1
Fixed in:5.15.0-1059.65USN-6766-1
Fixed in:6.5.0-1024.24USN-6819-2
linux-oracle-5.15Ubuntu
Fixed in:5.15.0-1059.65~20.04.1USN-6766-1
linux-oracle-5.4Ubuntu
Fixed in:5.4.0-1123.132~18.04.1USN-6767-1
linux-oracle-6.5Ubuntu
Fixed in:6.5.0-1024.24~22.04.1USN-6819-4
linux-raspiUbuntu
Fixed in:5.4.0-1108.120USN-6767-1
Fixed in:5.15.0-1054.57USN-6766-2
Fixed in:6.5.0-1018.21USN-6818-1
linux-raspi-5.4Ubuntu
Fixed in:5.4.0-1108.120~18.04.1USN-6767-1
linux-starfiveUbuntu
Fixed in:6.5.0-1015.16USN-6819-1
linux-starfive-6.5Ubuntu
Fixed in:6.5.0-1015.16~22.04.1USN-6819-1
linux-xilinx-zynqmpUbuntu
Fixed in:5.4.0-1043.47USN-6767-1

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged

Impact

ConfidentialityNone
IntegrityNone
AvailabilityHigh

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Exploit Intelligence

0.31%probability of exploitation in 30 days
23rdpercentile

Low risk: more likely to be exploited than 23% of all known CVEs.

References

Embed a live status badge for CVE-2023-52587
CVE-2023-52587 severity badge

Markdown

[![CVE-2023-52587](https://tridentstack.com/cve/badge/CVE-2023-52587.svg)](https://tridentstack.com/cve/CVE-2023-52587)

HTML

<a href="https://tridentstack.com/cve/CVE-2023-52587"><img src="https://tridentstack.com/cve/badge/CVE-2023-52587.svg" alt="CVE-2023-52587"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

Start free

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2025-02-14.