Bug 2268455 (CVE-2023-52488)
| Summary: | CVE-2023-52488 kernel: serial: sc16is7xx: convert from _raw_ to _noinc_ regmap functions for FIFO | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Mauro Matteo Cascella <mcascell> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | acaringi, allarkin, aquini, bhu, chwhite, cye, cyin, dbohanno, debarbos, dfreiber, drow, dvlasenk, esandeen, ezulian, hkrzesin, jarod, jburrell, jdenham, jfaracco, jforbes, jlelli, joe.lawrence, jshortt, jstancek, jwyatt, kcarcia, ldoskova, lgoncalv, lzampier, mleitner, mmilgram, mstowell, nmurray, ptalbert, rparrazo, rrobaina, rvrbovsk, scweaver, sidakwo, sukulkar, tglozar, vkumar, wcosta, williams, wmealing, ycote, ykopkova, zhijwang |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | kernel 6.1.76, kernel 6.6.15, kernel 6.7.3, kernel 6.8-rc1 | Doc Type: | If docs needed, set a value |
| Doc Text: |
A cache corruption vulnerability was found in the Linux kernel, which affects the regmap cache and is caused by the FIFO Read/Write (R/W) functions regmap_raw_read() and regmap_raw_write() during burst mode. These functions are able to perform IO operations over multiple registers, and if the regmap cache is not disabled manually during this mode, it can lead to cache corruption.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2268456 | ||
| Bug Blocks: | 2266913 | ||
|
Description
Mauro Matteo Cascella
2024-03-07 16:24:07 UTC
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 2268456] This was fixed for Fedora with eh 6.7.3 stable kernel updates. The result of automatic check (that is developed by Alexander Larkin) for this CVE-2023-52488 is: SKIP No affected files built, so skip this CVE NO - - unknown (where first YES/NO value means if related sources built). |