Lucene search

K
redhatcveRedhat.comRH:CVE-2023-52615
HistoryMar 18, 2024 - 1:52 p.m.

CVE-2023-52615

2024-03-1813:52:41
redhat.com
access.redhat.com
11
linux kernel
vulnerability
cve-2023-52615
hwrng
dead-lock
fix
page fault
mmap
recursive read
copy_to_user

5.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.2%

A vulnerability was found in the hwrng component of the Linux kernel, which caused a deadlock when reading from /dev/hwrng into memory and mmap-ed from /dev/hwrng. This issue is triggered by a recursive read during a page fault and allows a local, authenticated attacker to cause a denial of service.

Mitigation

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

5.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.2%