CVE-2023-52639

Severity CVSS v4.0:
Pending analysis
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
03/04/2024
Last modified:
17/03/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> KVM: s390: vsie: fix race during shadow creation<br /> <br /> Right now it is possible to see gmap-&gt;private being zero in<br /> kvm_s390_vsie_gmap_notifier resulting in a crash. This is due to the<br /> fact that we add gmap-&gt;private == kvm after creation:<br /> <br /> static int acquire_gmap_shadow(struct kvm_vcpu *vcpu,<br /> struct vsie_page *vsie_page)<br /> {<br /> [...]<br /> gmap = gmap_shadow(vcpu-&gt;arch.gmap, asce, edat);<br /> if (IS_ERR(gmap))<br /> return PTR_ERR(gmap);<br /> gmap-&gt;private = vcpu-&gt;kvm;<br /> <br /> Let children inherit the private field of the parent.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.8 (including) 6.1.82 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.22 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.7.6 (excluding)
cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc3:*:*:*:*:*:*