CVE-2023-53007
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/03/2025
Last modified:
30/10/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
tracing: Make sure trace_printk() can output as soon as it can be used<br />
<br />
Currently trace_printk() can be used as soon as early_trace_init() is<br />
called from start_kernel(). But if a crash happens, and<br />
"ftrace_dump_on_oops" is set on the kernel command line, all you get will<br />
be:<br />
<br />
[ 0.456075] -0 0dN.2. 347519us : Unknown type 6<br />
[ 0.456075] -0 0dN.2. 353141us : Unknown type 6<br />
[ 0.456075] -0 0dN.2. 358684us : Unknown type 6<br />
<br />
This is because the trace_printk() event (type 6) hasn&#39;t been registered<br />
yet. That gets done via an early_initcall(), which may be early, but not<br />
early enough.<br />
<br />
Instead of registering the trace_printk() event (and other ftrace events,<br />
which are not trace events) via an early_initcall(), have them registered at<br />
the same time that trace_printk() can be used. This way, if there is a<br />
crash before early_initcall(), then the trace_printk()s will actually be<br />
useful.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.12 (including) | 4.14.305 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.15 (including) | 4.19.272 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.20 (including) | 5.4.231 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.5 (including) | 5.10.166 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.91 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.9 (excluding) |
| cpe:2.3:o:linux:linux_kernel:6.2:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.2:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.2:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.2:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.2:rc5:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/198c83963f6335ca6d690cff067679560f2a3a22
- https://git.kernel.org/stable/c/3bb06eb6e9acf7c4a3e1b5bc87aed398ff8e2253
- https://git.kernel.org/stable/c/76b2390fdc80c0a8300e5da5b6b62d201b6fe9ce
- https://git.kernel.org/stable/c/b0af180514edea6c83dc9a299d9f383009c99f25
- https://git.kernel.org/stable/c/b94d7c7654356860dd7719120c7d15ba38b6162a
- https://git.kernel.org/stable/c/de3930a4883ddad2244efd6d349013294c62c75c
- https://git.kernel.org/stable/c/f97eb0ab066133483a65c93eb894748de2f6b598



