CVE-2023-53860

Description

A sleep-in-atomic-context bug was found in the Device Mapper subsystem in the Linux kernel. When processing REQ_NOWAIT requests, dm incorrectly submits I/O while holding an RCU read lock, assuming that REQ_NOWAIT means no scheduling can occur. However, mempool_alloc() and other allocation functions may still sleep, leading to sleeping function calls from invalid contexts. This can cause kernel warnings or crashes.

Statement

This is a sleeping-in-atomic-context bug in Device Mapper that can cause kernel warnings and potential issues when using O_DIRECT with RWF_NOWAIT flags on dm devices. The vulnerability requires local access and specific I/O patterns to trigger.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score4.7N/A7.8
Attack VectorLocalN/ALocal
Attack ComplexityHighN/ALow
Privileges RequiredLowN/ALow
User InteractionNoneN/ANone
ScopeUnchangedN/AUnchanged
ConfidentialityNoneN/AHigh
Integrity ImpactNoneN/AHigh
Availability ImpactHighN/AHigh

Vector

Red Hat: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

cve.org: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Understanding the Weakness (CWE)

Integrity,Confidentiality,Other

Technical Impact: Modify Memory; Read Memory; Modify Application Data; Read Application Data; Alter Execution Logic

Frequently Asked Questions

Want to get errata notifications? Sign up here.