CVE-2023-52801
Severity CVSS v4.0:
Pending analysis
Type:
CWE-284
Improper Access Control
Publication date:
21/05/2024
Last modified:
02/04/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
iommufd: Fix missing update of domains_itree after splitting iopt_area<br />
<br />
In iopt_area_split(), if the original iopt_area has filled a domain and is<br />
linked to domains_itree, pages_nodes have to be properly<br />
reinserted. Otherwise the domains_itree becomes corrupted and we will UAF.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.5.13 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.6 (including) | 6.6.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/836db2e7e4565d8218923b3552304a1637e2f28d
- https://git.kernel.org/stable/c/e7250ab7ca4998fe026f2149805b03e09dc32498
- https://git.kernel.org/stable/c/fcb32111f01ddf3cbd04644cde1773428e31de6a
- https://git.kernel.org/stable/c/836db2e7e4565d8218923b3552304a1637e2f28d
- https://git.kernel.org/stable/c/e7250ab7ca4998fe026f2149805b03e09dc32498
- https://git.kernel.org/stable/c/fcb32111f01ddf3cbd04644cde1773428e31de6a