HomeDefectsLIN1024-1583
Fixed

LIN1024-1583 : Security Advisory - linux - CVE-2023-52787

Created: May 21, 2024    Updated: Aug 28, 2024
Resolved Date: May 22, 2024
Found In Version: 10.24.33.1
Fix Version: 10.24.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

blk-mq: make sure active queue usage is held for bio_integrity_prep()

blk_integrity_unregister() can come if queue usage counter isn't held
for one bio with integrity prepared, so this request may be completed with
calling profile->complete_fn, then kernel panic.

Another constraint is that bio_integrity_prep() needs to be called
before bio merge.

Fix the issue by:

- call bio_integrity_prep() with one queue usage counter grabbed reliably

- call bio_integrity_prep() before bio merge

CREATE(Triage):(User=admin) CVE-2023-52787 (https://nvd.nist.gov/vuln/detail/CVE-2023-52787)

CVEs