Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-52615
HistoryMar 18, 2024 - 12:00 a.m.

CVE-2023-52615

2024-03-1800:00:00
ubuntu.com
ubuntu.com
10
linux
kernel
hwrng
vulnerability
resolved
dead-lock
fix
page fault
mmap
recursive read
stack buffer
copy_to_user
unix

7.6 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.2%

In the Linux kernel, the following vulnerability has been resolved: hwrng:
core - Fix page fault dead lock on mmap-ed hwrng There is a dead-lock in
the hwrng device read path. This triggers when the user reads from
/dev/hwrng into memory also mmap-ed from /dev/hwrng. The resulting page
fault triggers a recursive read which then dead-locks. Fix this by using a
stack buffer when calling copy_to_user.

Notes

Author Note
rodrigo-zaiden USN-6765-1 for linux-oem-6.5 wrongly stated that this CVE was fixed in version 6.5.0-1022.23. The mentioned notice was revoked and the state of the fix for linux-oem-6.5 was recovered to the previous state.
OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchlinux< 5.4.0-181.201UNKNOWN
ubuntu22.04noarchlinux< 5.15.0-106.116UNKNOWN
ubuntu23.10noarchlinux< 6.5.0-35.35UNKNOWN
ubuntu20.04noarchlinux-aws< 5.4.0-1124.134UNKNOWN
ubuntu22.04noarchlinux-aws< 5.15.0-1061.67UNKNOWN
ubuntu23.10noarchlinux-aws< 6.5.0-1020.20UNKNOWN
ubuntu20.04noarchlinux-aws-5.15< 5.15.0-1061.67~20.04.1UNKNOWN
ubuntu18.04noarchlinux-aws-5.4< 5.4.0-1124.134~18.04.1UNKNOWN
ubuntu22.04noarchlinux-aws-6.5< 6.5.0-1020.20~22.04.1UNKNOWN
ubuntu20.04noarchlinux-azure< 5.4.0-1129.136UNKNOWN
Rows per page:
1-10 of 661

References

7.6 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.2%