Resource Injection Affecting perf package, versions <0:4.18.0-553.16.1.el8_10


Severity

Recommended
high

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
0.04% (15th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL8-PERF-6462545
  • published19 Mar 2024
  • disclosed18 Mar 2024

Introduced: 18 Mar 2024

CVE-2023-52619  (opens in a new tab)
CWE-99  (opens in a new tab)

How to fix?

Upgrade RHEL:8 perf to version 0:4.18.0-553.16.1.el8_10 or higher.
This issue was patched in RHSA-2024:5101.

NVD Description

Note: Versions mentioned in the description apply only to the upstream perf package and not the perf package as distributed by RHEL. See How to fix? for RHEL:8 relevant fixed versions and status.

In the Linux kernel, the following vulnerability has been resolved:

pstore/ram: Fix crash when setting number of cpus to an odd number

When the number of cpu cores is adjusted to 7 or other odd numbers, the zone size will become an odd number. The address of the zone will become: addr of zone0 = BASE addr of zone1 = BASE + zone_size addr of zone2 = BASE + zone_size*2 ... The address of zone1/3/5/7 will be mapped to non-alignment va. Eventually crashes will occur when accessing these va.

So, use ALIGN_DOWN() to make sure the zone size is even to avoid this bug.

CVSS Scores

version 3.1