Wind River Support Network

HomeDefectsLIN1023-4285
Fixed

LIN1023-4285 : Security Advisory - linux - CVE-2023-52619

Created: Mar 18, 2024    Updated: Apr 27, 2024
Resolved Date: Apr 19, 2024
Found In Version: 10.23.30.1
Fix Version: 10.23.30.9
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

pstore/ram: Fix crash when setting number of cpus to an odd number

When the number of cpu cores is adjusted to 7 or other odd numbers,
the zone size will become an odd number.
The address of the zone will become:
    addr of zone0 = BASE
    addr of zone1 = BASE + zone_size
    addr of zone2 = BASE + zone_size*2
    ...
The address of zone1/3/5/7 will be mapped to non-alignment va.
Eventually crashes will occur when accessing these va.

So, use ALIGN_DOWN() to make sure the zone size is even
to avoid this bug.

CREATE(Triage):(User=admin) CVE-2023-52619 (https://nvd.nist.gov/vuln/detail/CVE-2023-52619)

CVEs


Live chat
Online