SB20240702120 - Input validation error in Linux kernel include asm
Published: July 2, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2023-52677)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the ALIGN() function in arch/riscv/kernel/vmlinux.lds.S, within the INIT_TEXT_SECTION() function in arch/riscv/kernel/vmlinux-xip.lds.S, within the is_kernel_exittext() and patch_map() functions in arch/riscv/kernel/patch.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/938f70d14618ec72e10d6fcf8a546134136d7c13
- https://git.kernel.org/stable/c/890cfe5337e0aaf03ece1429db04d23c88da72e7
- https://git.kernel.org/stable/c/8db56df4a954b774bdc68917046a685a9fa2e4bc
- https://git.kernel.org/stable/c/1d7a03052846f34d624d0ab41a879adf5e85c85f
- https://git.kernel.org/stable/c/420370f3ae3d3b883813fd3051a38805160b2b9f
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.148
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.75
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.14
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.7.2
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.8