Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-52481— arm64: errata: Add Cortex-A520 speculative unprivileged load workaround

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞。攻击者利用该漏洞可以获取敏感信息。

AI Predicted 5.3 Difficulty: Hard EPSS 0.60% · P47

Possible ATT&CK Techniques 1 AI

T1570 · Lateral Tool Transfer

Affected Version Matrix 8

VendorProduct Version RangeStatus
Linux Linux 60ffc30d5652810dd34ea2eec41504222f5d5791< 6e3ae2927b432a3b7c8374f14dbc1bd9ebe4372c affected
60ffc30d5652810dd34ea2eec41504222f5d5791< 32b0a4ffcaea44a00a61e40c0d1bcc50362aee25 affected
60ffc30d5652810dd34ea2eec41504222f5d5791< 471470bc7052d28ce125901877dd10e4c048e513 affected
3.7 affected
< 3.7 unaffected
6.1.57≤ 6.1.* unaffected
6.5.7≤ 6.5.* unaffected
6.6≤ * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-52481

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
arm64: errata: Add Cortex-A520 speculative unprivileged load workaround
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Add Cortex-A520 speculative unprivileged load workaround Implement the workaround for ARM Cortex-A520 erratum 2966298. On an affected Cortex-A520 core, a speculatively executed unprivileged load might leak data from a privileged load via a cache side channel. The issue only exists for loads within a translation regime with the same translation (e.g. same ASID and VMID). Therefore, the issue only affects the return to EL0. The workaround is to execute a TLBI before returning to EL0 after all loads of privileged data. A non-shareable TLBI to any address is sufficient. The workaround isn't necessary if page table isolation (KPTI) is enabled, but for simplicity it will be. Page table isolation should normally be disabled for Cortex-A520 as it supports the CSV3 feature and the E0PD feature (used when KASLR is enabled).
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞。攻击者利用该漏洞可以获取敏感信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 60ffc30d5652810dd34ea2eec41504222f5d5791 ~ 6e3ae2927b432a3b7c8374f14dbc1bd9ebe4372c -
Linux Linux 3.7 -

II. Public POCs for CVE-2023-52481

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-52481

请登录查看更多情报信息。

Patches & Fixes for CVE-2023-52481 (1)

Other References for CVE-2023-52481 (2)

Same Patch Batch · Linux · 2024-02-29 · 53 CVEs total

CVE-2023-52480 9.8 CRITICAL ksmbd: fix race condition between session lookup and expire
CVE-2023-52478 8.8 HIGH HID: logitech-hidpp: Fix kernel crash on receiver USB disconnect
CVE-2023-52479 8.8 HIGH ksmbd: fix uaf in smb20_oplock_break_ack
CVE-2024-26620 8.2 HIGH s390/vfio-ap: always filter entire AP matrix
CVE-2021-47061 7.8 HIGH KVM: Destroy I/O bus devices on unregister failure _after_ sync'ing SRCU
CVE-2023-52486 7.8 HIGH drm: Don't unref the same fb many times by mistake due to deadlock handling
CVE-2023-52483 7.8 HIGH mctp: perform route lookups under a RCU read-side lock
CVE-2021-47068 7.8 HIGH net/nfc: fix use-after-free llcp_sock_bind/connect
CVE-2023-52491 7.8 HIGH media: mtk-jpeg: Fix use after free bug due to error path handling in mtk_jpeg_dec_device_
CVE-2021-47060 7.8 HIGH KVM: Stop looking for coalesced MMIO zones if the bus is destroyed
CVE-2024-26608 7.8 HIGH ksmbd: fix global oob in ksmbd_nl_policy
CVE-2024-26610 7.8 HIGH wifi: iwlwifi: fix a memory corruption
CVE-2024-26614 7.8 HIGH tcp: make sure init the accept_queue's spinlocks once
CVE-2024-26617 7.8 HIGH fs/proc/task_mmu: move mmu notification mechanism inside mm lock
CVE-2024-26611 7.5 HIGH xsk: fix usage of multi-buffer BPF helpers for ZC XDP
CVE-2023-52497 7.1 HIGH erofs: fix lz4 inplace decompression
CVE-2021-47066 7.1 HIGH async_xor: increase src_offs when dropping destination page
CVE-2021-47055 7.1 HIGH mtd: require write permissions for locking and badblock ioctls
CVE-2021-47063 drm: bridge/panel: Cleanup connector on bridge detach
CVE-2021-47016 m68k: mvme147,mvme16x: Don't wipe PCC timer config bits

Showing top 20 of 53 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-52481

No comments yet


Leave a comment