vulnerability
Ubuntu: (Multiple Advisories) (CVE-2023-52617): Linux kernel vulnerabilities
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
4 | (AV:L/AC:L/Au:M/C:N/I:N/A:C) | 03/18/2024 | 05/17/2024 | 02/18/2025 |
Description
In the Linux kernel, the following vulnerability has been resolved:
PCI: switchtec: Fix stdev_release() crash after surprise hot remove
A PCI device hot removal may occur while stdev->cdev is held open. The call
to stdev_release() then happens during close or exit, at a point way past
switchtec_pci_remove(). Otherwise the last ref would vanish with the
trailing put_device(), just before return.
At that later point in time, the devm cleanup has already removed the
stdev->mmio_mrpc mapping. Also, the stdev->pdev reference was not a counted
one. Therefore, in DMA mode, the iowrite32() in stdev_release() will cause
a fatal page fault, and the subsequent dma_free_coherent(), if reached,
would pass a stale &stdev->pdev->dev pointer.
Fix by moving MRPC DMA shutdown into switchtec_pci_remove(), after
stdev_kill(). Counting the stdev->pdev ref is now optional, but may prevent
future accidents.
Reproducible via the script at
https://lore.kernel.org/r/[email protected]
Solution(s)
References
- CVE-2023-52617
- https://attackerkb.com/topics/CVE-2023-52617
- UBUNTU-USN-6765-1
- UBUNTU-USN-6766-1
- UBUNTU-USN-6766-2
- UBUNTU-USN-6766-3
- UBUNTU-USN-6767-1
- UBUNTU-USN-6767-2
- UBUNTU-USN-6795-1
- UBUNTU-USN-6818-1
- UBUNTU-USN-6818-2
- UBUNTU-USN-6818-3
- UBUNTU-USN-6818-4
- UBUNTU-USN-6819-1
- UBUNTU-USN-6819-2
- UBUNTU-USN-6819-3
- UBUNTU-USN-6819-4
- UBUNTU-USN-6828-1

Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.