SB2024062539 - Resource management error in Linux kernel fs
Published: June 25, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2023-52654)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the scm_fp_copy() function in net/core/scm.c, within the io_finish_async() and io_sqe_files_register() functions in fs/io_uring.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/18824f592aad4124d79751bbc1500ea86ac3ff29
- https://git.kernel.org/stable/c/3fe1ea5f921bf5b71cbfdc4469fb96c05936610e
- https://git.kernel.org/stable/c/bcedd497b3b4a0be56f3adf7c7542720eced0792
- https://git.kernel.org/stable/c/f2f57f51b53be153a522300454ddb3887722fb2c
- https://git.kernel.org/stable/c/5a33d385eb36991a91e3dddb189d8679e2aac2be
- https://git.kernel.org/stable/c/705318a99a138c29a512a72c3e0043b3cd7f55f4
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.204
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.143
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.264
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.68
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.7
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.7