Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-52516— dma-debug: don't call __dma_entry_alloc_check_leak() under free_entries_lock

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于允许在 free_entries_lock 下调用 __dma_entry_alloc_check_leak()。

AI Predicted 4.4 Difficulty: Theoretical EPSS 0.17% · P6

Possible ATT&CK Techniques 1 AI

T1562.008

Affected Version Matrix 12

VendorProduct Version RangeStatus
Linux Linux ceb51173b2b5bd7af0d99079f6bbacdcfc58fe08< c79300599923daaa30f417c75555d5566b3d31ae affected
ceb51173b2b5bd7af0d99079f6bbacdcfc58fe08< ac0d068099349cbca3d93f2e3b15bb329364b08c affected
ceb51173b2b5bd7af0d99079f6bbacdcfc58fe08< be8f49029eca3efbad0d74dbff3cb9129994ffab affected
ceb51173b2b5bd7af0d99079f6bbacdcfc58fe08< fe2b811a02c3244ebf6059039e4a9e715e26a9e3 affected
ceb51173b2b5bd7af0d99079f6bbacdcfc58fe08< fb5a4315591dae307a65fc246ca80b5159d296e1 affected
5.0 affected
< 5.0 unaffected
5.10.198≤ 5.10.* unaffected
… +4 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-52516

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
dma-debug: don't call __dma_entry_alloc_check_leak() under free_entries_lock
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: dma-debug: don't call __dma_entry_alloc_check_leak() under free_entries_lock __dma_entry_alloc_check_leak() calls into printk -> serial console output (qcom geni) and grabs port->lock under free_entries_lock spin lock, which is a reverse locking dependency chain as qcom_geni IRQ handler can call into dma-debug code and grab free_entries_lock under port->lock. Move __dma_entry_alloc_check_leak() call out of free_entries_lock scope so that we don't acquire serial console's port->lock under it. Trimmed-down lockdep splat: The existing dependency chain (in reverse order) is: -> #2 (free_entries_lock){-.-.}-{2:2}: _raw_spin_lock_irqsave+0x60/0x80 dma_entry_alloc+0x38/0x110 debug_dma_map_page+0x60/0xf8 dma_map_page_attrs+0x1e0/0x230 dma_map_single_attrs.constprop.0+0x6c/0xc8 geni_se_rx_dma_prep+0x40/0xcc qcom_geni_serial_isr+0x310/0x510 __handle_irq_event_percpu+0x110/0x244 handle_irq_event_percpu+0x20/0x54 handle_irq_event+0x50/0x88 handle_fasteoi_irq+0xa4/0xcc handle_irq_desc+0x28/0x40 generic_handle_domain_irq+0x24/0x30 gic_handle_irq+0xc4/0x148 do_interrupt_handler+0xa4/0xb0 el1_interrupt+0x34/0x64 el1h_64_irq_handler+0x18/0x24 el1h_64_irq+0x64/0x68 arch_local_irq_enable+0x4/0x8 ____do_softirq+0x18/0x24 ... -> #1 (&port_lock_key){-.-.}-{2:2}: _raw_spin_lock_irqsave+0x60/0x80 qcom_geni_serial_console_write+0x184/0x1dc console_flush_all+0x344/0x454 console_unlock+0x94/0xf0 vprintk_emit+0x238/0x24c vprintk_default+0x3c/0x48 vprintk+0xb4/0xbc _printk+0x68/0x90 register_console+0x230/0x38c uart_add_one_port+0x338/0x494 qcom_geni_serial_probe+0x390/0x424 platform_probe+0x70/0xc0 really_probe+0x148/0x280 __driver_probe_device+0xfc/0x114 driver_probe_device+0x44/0x100 __device_attach_driver+0x64/0xdc bus_for_each_drv+0xb0/0xd8 __device_attach+0xe4/0x140 device_initial_probe+0x1c/0x28 bus_probe_device+0x44/0xb0 device_add+0x538/0x668 of_device_add+0x44/0x50 of_platform_device_create_pdata+0x94/0xc8 of_platform_bus_create+0x270/0x304 of_platform_populate+0xac/0xc4 devm_of_platform_populate+0x60/0xac geni_se_probe+0x154/0x160 platform_probe+0x70/0xc0 ... -> #0 (console_owner){-...}-{0:0}: __lock_acquire+0xdf8/0x109c lock_acquire+0x234/0x284 console_flush_all+0x330/0x454 console_unlock+0x94/0xf0 vprintk_emit+0x238/0x24c vprintk_default+0x3c/0x48 vprintk+0xb4/0xbc _printk+0x68/0x90 dma_entry_alloc+0xb4/0x110 debug_dma_map_sg+0xdc/0x2f8 __dma_map_sg_attrs+0xac/0xe4 dma_map_sgtable+0x30/0x4c get_pages+0x1d4/0x1e4 [msm] msm_gem_pin_pages_locked+0x38/0xac [msm] msm_gem_pin_vma_locked+0x58/0x88 [msm] msm_ioctl_gem_submit+0xde4/0x13ac [msm] drm_ioctl_kernel+0xe0/0x15c drm_ioctl+0x2e8/0x3f4 vfs_ioctl+0x30/0x50 ... Chain exists of: console_owner --> &port_lock_key --> free_entries_lock Possible unsafe locking scenario: CPU0 CPU1 ---- ---- lock(free_entries_lock); lock(&port_lock_key); lock(free_entries_lock); lock(console_owner); *** DEADLOCK *** Call trace: dump_backtrace+0xb4/0xf0 show_stack+0x20/0x30 dump_stack_lvl+0x60/0x84 dump_stack+0x18/0x24 print_circular_bug+0x1cc/0x234 check_noncircular+0x78/0xac __lock_acquire+0xdf8/0x109c lock_acquire+0x234/0x284 console_flush_all+0x330/0x454 consol ---truncated---
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于允许在 free_entries_lock 下调用 __dma_entry_alloc_check_leak()。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux ceb51173b2b5bd7af0d99079f6bbacdcfc58fe08 ~ c79300599923daaa30f417c75555d5566b3d31ae -
Linux Linux 5.0 -

II. Public POCs for CVE-2023-52516

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-52516

请登录查看更多情报信息。

Other References for CVE-2023-52516 (5)

Same Patch Batch · Linux · 2024-03-02 · 57 CVEs total

CVE-2023-52515 9.8 CRITICAL RDMA/srp: Do not call scsi_done() from srp_abort()
CVE-2023-52522 8.8 HIGH net: fix possible store tearing in neigh_periodic_work()
CVE-2023-52502 8.8 HIGH net: nfc: fix races in nfc_llcp_sock_get() and nfc_llcp_sock_get_sn()
CVE-2023-52530 8.8 HIGH wifi: mac80211: fix potential key use-after-free
CVE-2024-26621 8.2 HIGH mm: huge_memory: don't force huge page alignment on 32 bit
CVE-2023-52574 7.8 HIGH team: fix null-ptr-deref when team device type is changed
CVE-2023-52523 7.8 HIGH bpf, sockmap: Reject sk_msg egress redirects to non-TCP sockets
CVE-2023-52509 7.8 HIGH ravb: Fix use-after-free issue in ravb_tx_timeout_work()
CVE-2023-52572 7.8 HIGH cifs: Fix UAF in cifs_demultiplex_thread()
CVE-2023-52517 7.8 HIGH spi: sun6i: fix race between DMA RX transfer completion and RX FIFO drain
CVE-2023-52503 7.8 HIGH tee: amdtee: fix use-after-free vulnerability in amdtee_close_session
CVE-2023-52513 7.5 HIGH RDMA/siw: Fix connection failure handling
CVE-2023-52565 7.1 HIGH media: uvcvideo: Fix OOB read
CVE-2023-52582 netfs: Only call folio_start_fscache() one time for each folio
CVE-2023-52561 arm64: dts: qcom: sdm845-db845c: Mark cont splash memory region as reserved
CVE-2023-52559 iommu/vt-d: Avoid memory allocation in iommu_suspend()
CVE-2023-52563 drm/meson: fix memory leak on ->hpd_notify callback
CVE-2023-52560 mm/damon/vaddr-test: fix memory leak in damon_do_test_apply_three_regions()
CVE-2023-52562 mm/slab_common: fix slab_caches list corruption after kmem_cache_destroy()
CVE-2023-52566 nilfs2: fix potential use after free in nilfs_gccache_submit_read_data()

Showing top 20 of 57 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-52516

No comments yet


Leave a comment