CVE-2023-52617: PCI: switchtec: Fix stdev_release() crash after surprise hot remove
In the Linux kernel, the following vulnerability has been resolved:
PCI: switchtec: Fix stdevrelease() crash after surprise hot remove
A PCI device hot removal may occur while stdev->cdev is held open. The call to stdevrelease() then happens during close or exit, at a point way past switchtecpciremove(). Otherwise the last ref would vanish with the trailing putdevice(), just before return.
At that later point in time, the devm cleanup has already removed the stdev->mmiomrpc mapping. Also, the stdev->pdev reference was not a counted one. Therefore, in DMA mode, the iowrite32() in stdevrelease() will cause a fatal page fault, and the subsequent dmafreecoherent(), if reached, would pass a stale &stdev->pdev->dev pointer.
Fix by moving MRPC DMA shutdown into switchtecpciremove(), after stdevkill(). Counting the stdev->pdev ref is now optional, but may prevent future accidents.
Reproducible via the script at https://lore.kernel.org/r/20231113212150.96410-1-dns@arista.com
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52617?
CVE-2023-52617 is classified as a moderate severity vulnerability in the Linux kernel.
How do I fix CVE-2023-52617?
To fix CVE-2023-52617, update the Linux kernel to versions 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.11-1, or 6.12.12-1.
What systems are affected by CVE-2023-52617?
CVE-2023-52617 affects systems running vulnerable versions of the Linux kernel related to PCI device hot removal.
Who is impacted by CVE-2023-52617?
Users and administrators of Linux systems with specific versions of the kernel that allow PCI device hot removal are impacted by CVE-2023-52617.
What causes the CVE-2023-52617 vulnerability?
CVE-2023-52617 is caused by a crash in the stdev_release() function when a PCI device is unexpectedly removed while still in use.