SB2024060848 - Information disclosure in Linux kernel hw hfi1 driver
Published: June 8, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2023-52747)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to information disclosure within the user_exp_rcv_setup() function in drivers/infiniband/hw/hfi1/file_ops.c. A local user can gain access to sensitive information.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/00d9e212b8a39e6ffcf31b9d2e503d2bf6009d45
- https://git.kernel.org/stable/c/7896accedf5bf1277d2f305718e36dc8bac7e321
- https://git.kernel.org/stable/c/79b595d9591426156a9e0635a5b5115508a36fef
- https://git.kernel.org/stable/c/9bae58d58b6bb73b572356b31a62d2afc7378d12
- https://git.kernel.org/stable/c/0a4f811f2e5d07bbd0c9226f4afb0a1270a831ae
- https://git.kernel.org/stable/c/6601fc0d15ffc20654e39486f9bef35567106d68
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.273
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.168
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.94
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.232
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.12
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2