CVE-2023-54024
Last modified
CVE-2023-54024 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: KVM: Destroy target device if coalesced MMIO unregistration fails Destroy and free the target coalesced MMIO device if unregistering said device fails. As clearly noted in the code, kvm_io_bus_unregister_dev() does not destroy the target device. BUG: memory leak unreferenced object 0xffff888112a54880 (size 64): comm "syz-executor.2", pid 5258, jiffies 4297861402 (age 14.129s) hex dump (first 32 bytes): 38 c7 67 15 00 c9 ff ff 38 c7 67 15 00 c9 ff ff 8.g.....8.g..... e0 c7 e1 83 ff ff ff ff 00 30 67 15 00 c9 ff ff .........0g..... backtrace: [<0000000006995a8a>] kmalloc include/linux/slab.h:556 [inline] [<0000000006995a8a>] kzalloc include/linux/slab.h:690 [inline] [<0000000006995a8a>] kvm_vm_ioctl_register_coalesced_mmio+0x8e/0x3d0 arch/x86/kvm/../../../virt/kvm/coalesced_mmio.c:150 [<00000000022550c2>] kvm_vm_ioctl+0x47d/0x1600 arch/x86/kvm/../../../virt/kvm/kvm_main.c:3323 [<000000008a75102f>] vfs_ioctl fs/ioctl.c:46 [inline] [<000000008a75102f>] file_ioctl fs/ioctl.c:509 [inline] [<000000008a75102f>] do_vfs_ioctl+0xbab/0x1160 fs/ioctl.c:696 [<0000000080e3f669>] ksys_ioctl+0x76/0xa0 fs/ioctl.c:713 [<0000000059ef4888>] __do_sys_ioctl fs/ioctl.c:720 [inline] [<0000000059ef4888>] __se_sys_ioctl fs/ioctl.c:718 [inline] [<0000000059ef4888>] __x64_sys_ioctl+0x6f/0xb0 fs/ioctl.c:718 [<000000006444fa05>] do_syscall_64+0x9f/0x4e0 arch/x86/entry/common.c:290 [<000000009a4ed50b>] entry_SYSCALL_64_after_hwframe+0x49/0xbe BUG: leak checking failed. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: KVM: Destroy target device if coalesced MMIO unregistration fails Destroy and free the target coalesced MMIO device if unregistering said device fails. As clearly noted in the code, kvm_io_bus_unregister_dev() does not destroy the target device. BUG: memory leak unreferenced object 0xffff888112a54880 (size 64): comm "syz-executor.2", pid 5258, jiffies 4297861402 (age 14.129s) hex dump (first 32 bytes): 38 c7 67 15 00 c9 ff ff 38 c7 67 15 00 c9 ff ff 8.g.....8.g..... e0 c7 e1 83 ff ff ff ff 00 30 67 15 00 c9 ff ff .........0g..... backtrace: [<0000000006995a8a>] kmalloc include/linux/slab.h:556 [inline] [<0000000006995a8a>] kzalloc include/linux/slab.h:690 [inline] [<0000000006995a8a>] kvm_vm_ioctl_register_coalesced_mmio+0x8e/0x3d0 arch/x86/kvm/../../../virt/kvm/coalesced_mmio.c:150 [<00000000022550c2>] kvm_vm_ioctl+0x47d/0x1600 arch/x86/kvm/../../../virt/kvm/kvm_main.c:3323 [<000000008a75102f>] vfs_ioctl fs/ioctl.c:46 [inline] [<000000008a75102f>] file_ioctl fs/ioctl.c:509 [inline] [<000000008a75102f>] do_vfs_ioctl+0xbab/0x1160 fs/ioctl.c:696 [<0000000080e3f669>] ksys_ioctl+0x76/0xa0 fs/ioctl.c:713 [<0000000059ef4888>] __do_sys_ioctl fs/ioctl.c:720 [inline] [<0000000059ef4888>] __se_sys_ioctl fs/ioctl.c:718 [inline] [<0000000059ef4888>] __x64_sys_ioctl+0x6f/0xb0 fs/ioctl.c:718 [<000000006444fa05>] do_syscall_64+0x9f/0x4e0 arch/x86/entry/common.c:290 [<000000009a4ed50b>] entry_SYSCALL_64_after_hwframe+0x49/0xbe BUG: leak checking failed
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 7d1bc32d6477ff96a32695ea4be8144e4513ab2d, < 10c2a20d73e99463e69b7e92706791656adc16d7; >= 2a20592baff59c5351c5200ec667e1a2aa22af85, < 76a9886e1b61ce5592df5ae78a19ed30399ae189; >= 5d3c4c79384af06e3c8e25b7770b6247496b4417, < 999439fd5da5a76253e2f2c37b94204f47d75491; >= 5d3c4c79384af06e3c8e25b7770b6247496b4417, < ccf6a7fb1aedb1472e1241ee55e4d26b68f8d066; >= 5d3c4c79384af06e3c8e25b7770b6247496b4417, < fb436dd6914325075f07d19851ab277b7a693ae7; >= 5d3c4c79384af06e3c8e25b7770b6247496b4417, < b1cb1fac22abf102ffeb29dd3eeca208a3869d54; 168e82f640ed1891a700bdb43e37da354b2ab63c; 50cbad42bfea8c052b7ca590bd4126cdc898713c; >= 5.4.119, < 5.4.235; >= 5.10.37, < 5.10.173; >= 5.11.21, < 5.12; >= 5.12.4, < 5.13 |
| Linux | Linux | 5.13 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2023-54024?
How severe is CVE-2023-54024?
How do I fix CVE-2023-54024?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-54019In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-5402 A CWE-269: Improper Privilege Management vulnerability ex…9.8
- CVE-2023-54020In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54021In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54022In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54023In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54025In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54026In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-54027In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54028In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54029Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2023-5403Server hostname translation to IP address manipulation which…8.1
Are you affected by CVE-2023-54024?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
