CVE-2023-52895

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/08/2024
Last modified:
11/09/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> io_uring/poll: don&amp;#39;t reissue in case of poll race on multishot request<br /> <br /> A previous commit fixed a poll race that can occur, but it&amp;#39;s only<br /> applicable for multishot requests. For a multishot request, we can safely<br /> ignore a spurious wakeup, as we never leave the waitqueue to begin with.<br /> <br /> A blunt reissue of a multishot armed request can cause us to leak a<br /> buffer, if they are ring provided. While this seems like a bug in itself,<br /> it&amp;#39;s not really defined behavior to reissue a multishot request directly.<br /> It&amp;#39;s less efficient to do so as well, and not required to rearm anything<br /> like it is for singleshot poll requests.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:6.1.7:*:*:*:*:*:*:*