Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-52489— mm/sparsemem: fix race in accessing memory_section->usage

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于访问memory_section->usage时存在竞争问题。

AI Predicted 5.5 Difficulty: Moderate EPSS 0.29% · P20

Affected Version Matrix 14

VendorProduct Version RangeStatus
Linux Linux f46edbd1b1516da1fb34c917775168d5df576f78< 90ad17575d26874287271127d43ef3c2af876cea affected
f46edbd1b1516da1fb34c917775168d5df576f78< b448de2459b6d62a53892487ab18b7d823ff0529 affected
f46edbd1b1516da1fb34c917775168d5df576f78< 68ed9e33324021e9d6b798e9db00ca3093d2012a affected
f46edbd1b1516da1fb34c917775168d5df576f78< 70064241f2229f7ba7b9599a98f68d9142e81a97 affected
f46edbd1b1516da1fb34c917775168d5df576f78< 3a01daace71b521563c38bbbf874e14c3e58adb7 affected
f46edbd1b1516da1fb34c917775168d5df576f78< 5ec8e8ea8b7783fab150cf86404fc38cb4db8800 affected
5.3 affected
< 5.3 unaffected
… +6 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-52489

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
mm/sparsemem: fix race in accessing memory_section->usage
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: mm/sparsemem: fix race in accessing memory_section->usage The below race is observed on a PFN which falls into the device memory region with the system memory configuration where PFN's are such that [ZONE_NORMAL ZONE_DEVICE ZONE_NORMAL]. Since normal zone start and end pfn contains the device memory PFN's as well, the compaction triggered will try on the device memory PFN's too though they end up in NOP(because pfn_to_online_page() returns NULL for ZONE_DEVICE memory sections). When from other core, the section mappings are being removed for the ZONE_DEVICE region, that the PFN in question belongs to, on which compaction is currently being operated is resulting into the kernel crash with CONFIG_SPASEMEM_VMEMAP enabled. The crash logs can be seen at [1]. compact_zone() memunmap_pages ------------- --------------- __pageblock_pfn_to_page ...... (a)pfn_valid(): valid_section()//return true (b)__remove_pages()-> sparse_remove_section()-> section_deactivate(): [Free the array ms->usage and set ms->usage = NULL] pfn_section_valid() [Access ms->usage which is NULL] NOTE: From the above it can be said that the race is reduced to between the pfn_valid()/pfn_section_valid() and the section deactivate with SPASEMEM_VMEMAP enabled. The commit b943f045a9af("mm/sparse: fix kernel crash with pfn_section_valid check") tried to address the same problem by clearing the SECTION_HAS_MEM_MAP with the expectation of valid_section() returns false thus ms->usage is not accessed. Fix this issue by the below steps: a) Clear SECTION_HAS_MEM_MAP before freeing the ->usage. b) RCU protected read side critical section will either return NULL when SECTION_HAS_MEM_MAP is cleared or can successfully access ->usage. c) Free the ->usage with kfree_rcu() and set ms->usage = NULL. No attempt will be made to access ->usage after this as the SECTION_HAS_MEM_MAP is cleared thus valid_section() return false. Thanks to David/Pavan for their inputs on this patch. [1] https://lore.kernel.org/linux-mm/994410bb-89aa-d987-1f50-f514903c55aa@quicinc.com/ On Snapdragon SoC, with the mentioned memory configuration of PFN's as [ZONE_NORMAL ZONE_DEVICE ZONE_NORMAL], we are able to see bunch of issues daily while testing on a device farm. For this particular issue below is the log. Though the below log is not directly pointing to the pfn_section_valid(){ ms->usage;}, when we loaded this dump on T32 lauterbach tool, it is pointing. [ 540.578056] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 [ 540.578068] Mem abort info: [ 540.578070] ESR = 0x0000000096000005 [ 540.578073] EC = 0x25: DABT (current EL), IL = 32 bits [ 540.578077] SET = 0, FnV = 0 [ 540.578080] EA = 0, S1PTW = 0 [ 540.578082] FSC = 0x05: level 1 translation fault [ 540.578085] Data abort info: [ 540.578086] ISV = 0, ISS = 0x00000005 [ 540.578088] CM = 0, WnR = 0 [ 540.579431] pstate: 82400005 (Nzcv daif +PAN -UAO +TCO -DIT -SSBSBTYPE=--) [ 540.579436] pc : __pageblock_pfn_to_page+0x6c/0x14c [ 540.579454] lr : compact_zone+0x994/0x1058 [ 540.579460] sp : ffffffc03579b510 [ 540.579463] x29: ffffffc03579b510 x28: 0000000000235800 x27:000000000000000c [ 540.579470] x26: 0000000000235c00 x25: 0000000000000068 x24:ffffffc03579b640 [ 540.579477] x23: 0000000000000001 x22: ffffffc03579b660 x21:0000000000000000 [ 540.579483] x20: 0000000000235bff x19: ffffffdebf7e3940 x18:ffffffdebf66d140 [ 540.579489] x17: 00000000739ba063 x16: 00000000739ba063 x15:00000000009f4bff [ 540.579495] x14: 0000008000000000 x13: 0000000000000000 x12:0000000000000001 [ 540.579501] x11: 0000000000000000 x10: 0000000000000000 x9 :ffffff897d2cd440 [ 540.579507] x8 : 0000000000000000 x7 : 0000000000000000 x6 :ffffffc03579b5b4 [ 540.579512] x5 : 0000000000027f25 x4 : ffffffc03579b5b8 x3 :0000000000000 ---truncated---
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于访问memory_section->usage时存在竞争问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux f46edbd1b1516da1fb34c917775168d5df576f78 ~ 90ad17575d26874287271127d43ef3c2af876cea -
Linux Linux 5.3 -

II. Public POCs for CVE-2023-52489

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-52489

请登录查看更多情报信息。

Mailing List Discussions for CVE-2023-52489 (1)

Other References for CVE-2023-52489 (5)

Same Patch Batch · Linux · 2024-02-29 · 53 CVEs total

CVE-2023-52480 9.8 CRITICAL ksmbd: fix race condition between session lookup and expire
CVE-2023-52478 8.8 HIGH HID: logitech-hidpp: Fix kernel crash on receiver USB disconnect
CVE-2023-52479 8.8 HIGH ksmbd: fix uaf in smb20_oplock_break_ack
CVE-2024-26620 8.2 HIGH s390/vfio-ap: always filter entire AP matrix
CVE-2021-47061 7.8 HIGH KVM: Destroy I/O bus devices on unregister failure _after_ sync'ing SRCU
CVE-2023-52483 7.8 HIGH mctp: perform route lookups under a RCU read-side lock
CVE-2021-47068 7.8 HIGH net/nfc: fix use-after-free llcp_sock_bind/connect
CVE-2023-52486 7.8 HIGH drm: Don't unref the same fb many times by mistake due to deadlock handling
CVE-2023-52491 7.8 HIGH media: mtk-jpeg: Fix use after free bug due to error path handling in mtk_jpeg_dec_device_
CVE-2021-47060 7.8 HIGH KVM: Stop looking for coalesced MMIO zones if the bus is destroyed
CVE-2024-26608 7.8 HIGH ksmbd: fix global oob in ksmbd_nl_policy
CVE-2024-26610 7.8 HIGH wifi: iwlwifi: fix a memory corruption
CVE-2024-26614 7.8 HIGH tcp: make sure init the accept_queue's spinlocks once
CVE-2024-26617 7.8 HIGH fs/proc/task_mmu: move mmu notification mechanism inside mm lock
CVE-2024-26611 7.5 HIGH xsk: fix usage of multi-buffer BPF helpers for ZC XDP
CVE-2021-47066 7.1 HIGH async_xor: increase src_offs when dropping destination page
CVE-2021-47055 7.1 HIGH mtd: require write permissions for locking and badblock ioctls
CVE-2023-52497 7.1 HIGH erofs: fix lz4 inplace decompression
CVE-2021-47054 bus: qcom: Put child node before return
CVE-2021-47065 rtw88: Fix array overrun in rtw_get_tx_power_params()

Showing top 20 of 53 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-52489

No comments yet


Leave a comment