« Volver al listado

CVE-2023-54007

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

vmci_host: fix a race condition in vmci_host_poll() causing GPF

During fuzzing, a general protection fault is observed in vmci_host_poll().

Example thread interleaving that causes the general protection fault is as follows:

In this scenario, vmci_host_poll() reads vmci_host_dev->context first, and then reads vmci_host_dev->ct_type to check that vmci_host_dev->context is initialized. However, since these two reads are not atomically executed, there is a chance of a race condition as described above.

To fix this race condition, read vmci_host_dev->context after checking the value of vmci_host_dev->ct_type so that vmci_host_poll() always reads an initialized context.

Detalles técnicos trazas, registros y código del informe original
general protection fault, probably for non-canonical address 0xdffffc0000000019: 0000 [#1] PREEMPT SMP KASAN
KASAN: null-ptr-deref in range [0x00000000000000c8-0x00000000000000cf]
RIP: 0010:__lock_acquire+0xf3/0x5e00 kernel/locking/lockdep.c:4926
<- omitting registers ->
Call Trace:
 <TASK>
 lock_acquire+0x1a4/0x4a0 kernel/locking/lockdep.c:5672
 __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]
 _raw_spin_lock_irqsave+0xb3/0x100 kernel/locking/spinlock.c:162
 add_wait_queue+0x3d/0x260 kernel/sched/wait.c:22
 poll_wait include/linux/poll.h:49 [inline]
 vmci_host_poll+0xf8/0x2b0 drivers/misc/vmw_vmci/vmci_host.c:174
 vfs_poll include/linux/poll.h:88 [inline]
 do_pollfd fs/select.c:873 [inline]
 do_poll fs/select.c:921 [inline]
 do_sys_poll+0xc7c/0x1aa0 fs/select.c:1015
 __do_sys_ppoll fs/select.c:1121 [inline]
 __se_sys_ppoll+0x2cc/0x330 fs/select.c:1101
 do_syscall_x64 arch/x86/entry/common.c:51 [inline]
 do_syscall_64+0x4e/0xa0 arch/x86/entry/common.c:82
 entry_SYSCALL_64_after_hwframe+0x46/0xb0

CPU1 (vmci_host_poll)               CPU2 (vmci_host_do_init_context)
-----                               -----
// Read uninitialized context
context = vmci_host_dev->context;
                                    // Initialize context
                                    vmci_host_dev->context = vmci_ctx_create();
                                    vmci_host_dev->ct_type = VMCIOBJ_CONTEXT;

if (vmci_host_dev->ct_type == VMCIOBJ_CONTEXT) {
    // Dereferencing the wrong pointer
    poll_wait(..., &context->host_context);
}

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-54007",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "8bf503991f87e32ea42a7bd69b79ba084fddc5d7",
              "lessThan": "2053e93ac15519ed1f1fe6eba79a33a4963be4a3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8bf503991f87e32ea42a7bd69b79ba084fddc5d7",
              "lessThan": "ca0f4ad2b7a36c799213ef0a213eb977a51e03dc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8bf503991f87e32ea42a7bd69b79ba084fddc5d7",
              "lessThan": "85b4aa4eb2e3a0da111fd0a1cdbf00f986ac6b6b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8bf503991f87e32ea42a7bd69b79ba084fddc5d7",
              "lessThan": "770d30b1355c6c8879973dd054fca9168def182c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8bf503991f87e32ea42a7bd69b79ba084fddc5d7",
              "lessThan": "d22b2a35729cb1de311cb650cd67518a24e13fc9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8bf503991f87e32ea42a7bd69b79ba084fddc5d7",
              "lessThan": "67e35824f861a05b44b19d38e16a83f653bd9d92",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8bf503991f87e32ea42a7bd69b79ba084fddc5d7",
              "lessThan": "ab64bd32b9fac27ff4737d63711b9db5e5462448",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8bf503991f87e32ea42a7bd69b79ba084fddc5d7",
              "lessThan": "ae13381da5ff0e8e084c0323c3cc0a945e43e9c7",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/misc/vmw_vmci/vmci_host.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.9"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.9",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "4.19.283",
              "versionType": "semver",
              "lessThanOrEqual": "4.19.*"
            },
            {
              "status": "unaffected",
              "version": "5.4.243",
              "versionType": "semver",
              "lessThanOrEqual": "5.4.*"
            },
            {
              "status": "unaffected",
              "version": "5.10.180",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.111",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.28",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.2.15",
              "versionType": "semver",
              "lessThanOrEqual": "6.2.*"
            },
            {
              "status": "unaffected",
              "version": "6.3.2",
              "versionType": "semver",
              "lessThanOrEqual": "6.3.*"
            },
            {
              "status": "unaffected",
              "version": "6.4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/misc/vmw_vmci/vmci_host.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-12-24T11:15:53.633",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2053e93ac15519ed1f1fe6eba79a33a4963be4a3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/67e35824f861a05b44b19d38e16a83f653bd9d92",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/770d30b1355c6c8879973dd054fca9168def182c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/85b4aa4eb2e3a0da111fd0a1cdbf00f986ac6b6b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ab64bd32b9fac27ff4737d63711b9db5e5462448",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ae13381da5ff0e8e084c0323c3cc0a945e43e9c7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ca0f4ad2b7a36c799213ef0a213eb977a51e03dc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d22b2a35729cb1de311cb650cd67518a24e13fc9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvmci_host: fix a race condition in vmci_host_poll() causing GPF\n\nDuring fuzzing, a general protection fault is observed in\nvmci_host_poll().\n\ngeneral protection fault, probably for non-canonical address 0xdffffc0000000019: 0000 [#1] PREEMPT SMP KASAN\nKASAN: null-ptr-deref in range [0x00000000000000c8-0x00000000000000cf]\nRIP: 0010:__lock_acquire+0xf3/0x5e00 kernel/locking/lockdep.c:4926\n<- omitting registers ->\nCall Trace:\n <TASK>\n lock_acquire+0x1a4/0x4a0 kernel/locking/lockdep.c:5672\n __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]\n _raw_spin_lock_irqsave+0xb3/0x100 kernel/locking/spinlock.c:162\n add_wait_queue+0x3d/0x260 kernel/sched/wait.c:22\n poll_wait include/linux/poll.h:49 [inline]\n vmci_host_poll+0xf8/0x2b0 drivers/misc/vmw_vmci/vmci_host.c:174\n vfs_poll include/linux/poll.h:88 [inline]\n do_pollfd fs/select.c:873 [inline]\n do_poll fs/select.c:921 [inline]\n do_sys_poll+0xc7c/0x1aa0 fs/select.c:1015\n __do_sys_ppoll fs/select.c:1121 [inline]\n __se_sys_ppoll+0x2cc/0x330 fs/select.c:1101\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x4e/0xa0 arch/x86/entry/common.c:82\n entry_SYSCALL_64_after_hwframe+0x46/0xb0\n\nExample thread interleaving that causes the general protection fault\nis as follows:\n\nCPU1 (vmci_host_poll)               CPU2 (vmci_host_do_init_context)\n-----                               -----\n// Read uninitialized context\ncontext = vmci_host_dev->context;\n                                    // Initialize context\n                                    vmci_host_dev->context = vmci_ctx_create();\n                                    vmci_host_dev->ct_type = VMCIOBJ_CONTEXT;\n\nif (vmci_host_dev->ct_type == VMCIOBJ_CONTEXT) {\n    // Dereferencing the wrong pointer\n    poll_wait(..., &context->host_context);\n}\n\nIn this scenario, vmci_host_poll() reads vmci_host_dev->context first,\nand then reads vmci_host_dev->ct_type to check that\nvmci_host_dev->context is initialized. However, since these two reads\nare not atomically executed, there is a chance of a race condition as\ndescribed above.\n\nTo fix this race condition, read vmci_host_dev->context after checking\nthe value of vmci_host_dev->ct_type so that vmci_host_poll() always\nreads an initialized context."
    }
  ],
  "lastModified": "2026-06-17T06:46:31.600",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}