CVE-2023-52801: iommufd: Fix missing update of domains_itree after splitting iopt_area
In the Linux kernel, the following vulnerability has been resolved:
iommufd: Fix missing update of domainsitree after splitting ioptarea
In ioptareasplit(), if the original ioptarea has filled a domain and is linked to domainsitree, pagesnodes have to be properly reinserted. Otherwise the domainsitree becomes corrupted and we will UAF.
Other sources
In the Linux kernel, the following vulnerability has been resolved:
iommufd: Fix missing update of domainsitree after splitting ioptarea
The Linux kernel CVE team has assigned CVE-2023-52801 to this issue.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024052159-CVE-2023-52801-b287@gregkh/T
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.5.13 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.6.3 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.7
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52801?
The severity of CVE-2023-52801 has not been explicitly rated, but it addresses a vulnerability in the Linux kernel affecting the memory management functionality.
How do I fix CVE-2023-52801?
To fix CVE-2023-52801, update the Linux kernel to version 6.5.13, 6.6.3, or 6.7 as provided by Red Hat.
What versions of Linux are affected by CVE-2023-52801?
CVE-2023-52801 affects Linux kernel versions up to 6.5.13 and versions between 6.6 and 6.6.3.
Is CVE-2023-52801 related to memory management in Linux?
Yes, CVE-2023-52801 is related to the management of memory in the Linux kernel, specifically the handling of iopt_area.
Who should be concerned about CVE-2023-52801?
Administrators of systems running affected Linux kernel versions, particularly within environments using Red Hat packages, should be concerned about CVE-2023-52801.