CVE-2023-53814
Last modified
CVE-2023-53814 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: PCI: Fix dropping valid root bus resources with .end = zero On r8a7791/koelsch: kmemleak: 1 new suspected memory leaks (see /sys/kernel/debug/kmemleak) # cat /sys/kernel/debug/kmemleak unreferenced object 0xc3a34e00 (size 64): comm "swapper/0", pid 1, jiffies 4294937460 (age 199.080s) hex dump (first 32 bytes): b4 5d 81 f0 b4 5d 81 f0 c0 b0 a2 c3 00 00 00 00 .]...].......... 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [<fe3aa979>] __kmalloc+0xf0/0x140 [<34bd6bc0>] resource_list_create_entry+0x18/0x38 [<767046bc>] pci_add_resource_offset+0x20/0x68 [<b3f3edf2>] devm_of_pci_get_host_bridge_resources.constprop.0+0xb0/0x390 When coalescing two resources for a contiguous aperture, the second resource is enlarged to cover the full contiguous range, while the first resource is marked invalid. This invalidation is done by clearing the flags, start, and end members. When adding the initial resources to the bus later, invalid resources are skipped. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: PCI: Fix dropping valid root bus resources with .end = zero On r8a7791/koelsch: kmemleak: 1 new suspected memory leaks (see /sys/kernel/debug/kmemleak) # cat /sys/kernel/debug/kmemleak unreferenced object 0xc3a34e00 (size 64): comm "swapper/0", pid 1, jiffies 4294937460 (age 199.080s) hex dump (first 32 bytes): b4 5d 81 f0 b4 5d 81 f0 c0 b0 a2 c3 00 00 00 00 .]...].......... 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [<fe3aa979>] __kmalloc+0xf0/0x140 [<34bd6bc0>] resource_list_create_entry+0x18/0x38 [<767046bc>] pci_add_resource_offset+0x20/0x68 [<b3f3edf2>] devm_of_pci_get_host_bridge_resources.constprop.0+0xb0/0x390 When coalescing two resources for a contiguous aperture, the second resource is enlarged to cover the full contiguous range, while the first resource is marked invalid. This invalidation is done by clearing the flags, start, and end members. When adding the initial resources to the bus later, invalid resources are skipped. Unfortunately, the check for an invalid resource considers only the end member, causing false positives. E.g. on r8a7791/koelsch, root bus resource 0 ("bus 00") is skipped, and no longer registered with pci_bus_insert_busn_res() (causing the memory leak), nor printed: pci-rcar-gen2 ee090000.pci: host bridge /soc/pci@ee090000 ranges: pci-rcar-gen2 ee090000.pci: MEM 0x00ee080000..0x00ee08ffff -> 0x00ee080000 pci-rcar-gen2 ee090000.pci: PCI: revision 11 pci-rcar-gen2 ee090000.pci: PCI host bridge to bus 0000:00 -pci_bus 0000:00: root bus resource [bus 00] pci_bus 0000:00: root bus resource [mem 0xee080000-0xee08ffff] Fix this by only skipping resources where all of the flags, start, and end members are zero.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= fd168b7d1d7cfc61cea561b1e3cc47aefc9e8f19, < e4af080f3ef6a65b0d702988c2471a47c9ae2cc0; >= 7c3855c423b17f6ca211858afb0cef20569914c7, < fe6a1fbe83f5b23d7db93596b793561230f06b40; >= 7c3855c423b17f6ca211858afb0cef20569914c7, < 7e6f2714d93cdf977b6124a80af2cf0e14e2d407; >= 7c3855c423b17f6ca211858afb0cef20569914c7, < 9d8ba74a181b1c81def21168795ed96cbe6f05ed |
| Linux | Linux | 5.16 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2023-53814?
How severe is CVE-2023-53814?
How do I fix CVE-2023-53814?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-53809In the Linux kernel, the following vulnerability has been re…
- CVE-2023-5381The Elementor Addon Elements plugin for WordPress is vulnera…4.8
- CVE-2023-53810In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-53811In the Linux kernel, the following vulnerability has been re…
- CVE-2023-53812In the Linux kernel, the following vulnerability has been re…
- CVE-2023-53813In the Linux kernel, the following vulnerability has been re…
- CVE-2023-53815In the Linux kernel, the following vulnerability has been re…
- CVE-2023-53816In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-53817In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2023-53818In the Linux kernel, the following vulnerability has been re…
- CVE-2023-53819In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-5382The Funnelforms Free plugin for WordPress is vulnerable to C…4.3
Are you affected by CVE-2023-53814?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
