CVE-2023-54117

Description

A kernel crash vulnerability was found in the Linux kernel's s390 dcssblk driver. Missing dax_remove_host() calls in the device removal path, combined with broken error handling in the device add path, cause stale xarray entries and list_add corruption. When a previously used gendisk pointer is reused, the kernel crashes with list corruption during subsequent device operations.

Statement

This flaw affects IBM s390 systems using the dcssblk driver for DCSS (Discontiguous Saved Segments) block devices. The crash occurs after device add/remove cycles when the same gendisk pointer is reused. This is an s390-specific issue and does not affect other architectures.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score5.5N/AN/A
Attack VectorLocalN/AN/A
Attack ComplexityLowN/AN/A
Privileges RequiredLowN/AN/A
User InteractionNoneN/AN/A
ScopeUnchangedN/AN/A
ConfidentialityNoneN/AN/A
Integrity ImpactNoneN/AN/A
Availability ImpactHighN/AN/A

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Understanding the Weakness (CWE)

Other,Confidentiality,Integrity

Technical Impact: Other; Read Application Data; Modify Application Data; DoS: Resource Consumption (Other)

It is possible to overflow the number of temporary files because directories typically have limits on the number of files allowed. This could create a denial of service problem.

Frequently Asked Questions

Want to get errata notifications? Sign up here.