CVE-2023-52859
In the Linux kernel, the following vulnerability has been resolved: perf: hisi: Fix use-after-free when register pmu fails When we fail to register the uncore pmu, the pmu context may not been allocated.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.24%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: perf: hisi: Fix use-after-free when register pmu fails When we fail to register the uncore pmu, the pmu context may not been allocated. The error handing will call cpuhp_state_remove_instance() to call uncore pmu offline callback, which migrate the pmu context. Since that's liable to lead to some kind of use-after-free. Use cpuhp_state_remove_instance_nocalls() instead of cpuhp_state_remove_instance() so that the notifiers don't execute after the PMU device has been failed to register.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.24% probability · 15th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/0e1e88bba286621b886218363de07b319d6208b2Patch
- https://git.kernel.org/stable/c/3405f364f82d4f5407a8b4c519dc15d24b847fdaPatch
- https://git.kernel.org/stable/c/75bab28ffd05ec8879c197890b1bd1dfec8d3f63Patch
- https://git.kernel.org/stable/c/b660420f449d094b1fabfa504889810b3a63cdd5Patch
- https://git.kernel.org/stable/c/b805cafc604bfdb671fae7347a57f51154afa735Patch
- https://git.kernel.org/stable/c/0e1e88bba286621b886218363de07b319d6208b2Patch
- https://git.kernel.org/stable/c/3405f364f82d4f5407a8b4c519dc15d24b847fdaPatch
- https://git.kernel.org/stable/c/75bab28ffd05ec8879c197890b1bd1dfec8d3f63Patch
- https://git.kernel.org/stable/c/b660420f449d094b1fabfa504889810b3a63cdd5Patch
- https://git.kernel.org/stable/c/b805cafc604bfdb671fae7347a57f51154afa735Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.