« Volver al listado

CVE-2023-54060

Estado: AplazadaAlta (8.8)—

In the Linux kernel, the following vulnerability has been resolved:

iommufd: Set end correctly when doing batch carry

Even though the test suite covers this it somehow became obscured that this wasn't working.

The test iommufd_ioas.mock_domain.access_domain_destory would blow up rarely.

end should be set to 1 because this just pushed an item, the carry, to the pfns list.

Sometimes the test would blow up with:

Detalles técnicos trazas, registros y código del informe original
  BUG: kernel NULL pointer dereference, address: 0000000000000000
  #PF: supervisor read access in kernel mode
  #PF: error_code(0x0000) - not-present page
  PGD 0 P4D 0
  Oops: 0000 [#1] SMP
  CPU: 5 PID: 584 Comm: iommufd Not tainted 6.5.0-rc1-dirty #1236
  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014
  RIP: 0010:batch_unpin+0xa2/0x100 [iommufd]
  Code: 17 48 81 fe ff ff 07 00 77 70 48 8b 15 b7 be 97 e2 48 85 d2 74 14 48 8b 14 fa 48 85 d2 74 0b 40 0f b6 f6 48 c1 e6 04 48 01 f2 <48> 8b 3a 48 c1 e0 06 89 ca 48 89 de 48 83 e7 f0 48 01 c7 e8 96 dc
  RSP: 0018:ffffc90001677a58 EFLAGS: 00010246
  RAX: 00007f7e2646f000 RBX: 0000000000000000 RCX: 0000000000000001
  RDX: 0000000000000000 RSI: 00000000fefc4c8d RDI: 0000000000fefc4c
  RBP: ffffc90001677a80 R08: 0000000000000048 R09: 0000000000000200
  R10: 0000000000030b98 R11: ffffffff81f3bb40 R12: 0000000000000001
  R13: ffff888101f75800 R14: ffffc90001677ad0 R15: 00000000000001fe
  FS:  00007f9323679740(0000) GS:ffff8881ba540000(0000) knlGS:0000000000000000
  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
  CR2: 0000000000000000 CR3: 0000000105ede003 CR4: 00000000003706a0
  DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
  DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
  Call Trace:
   <TASK>
   ? show_regs+0x5c/0x70
   ? __die+0x1f/0x60
   ? page_fault_oops+0x15d/0x440
   ? lock_release+0xbc/0x240
   ? exc_page_fault+0x4a4/0x970
   ? asm_exc_page_fault+0x27/0x30
   ? batch_unpin+0xa2/0x100 [iommufd]
   ? batch_unpin+0xba/0x100 [iommufd]
   __iopt_area_unfill_domain+0x198/0x430 [iommufd]
   ? __mutex_lock+0x8c/0xb80
   ? __mutex_lock+0x6aa/0xb80
   ? xa_erase+0x28/0x30
   ? iopt_table_remove_domain+0x162/0x320 [iommufd]
   ? lock_release+0xbc/0x240
   iopt_area_unfill_domain+0xd/0x10 [iommufd]
   iopt_table_remove_domain+0x195/0x320 [iommufd]
   iommufd_hw_pagetable_destroy+0xb3/0x110 [iommufd]
   iommufd_object_destroy_user+0x8e/0xf0 [iommufd]
   iommufd_device_detach+0xc5/0x140 [iommufd]
   iommufd_selftest_destroy+0x1f/0x70 [iommufd]
   iommufd_object_destroy_user+0x8e/0xf0 [iommufd]
   iommufd_destroy+0x3a/0x50 [iommufd]
   iommufd_fops_ioctl+0xfb/0x170 [iommufd]
   __x64_sys_ioctl+0x40d/0x9a0
   do_syscall_64+0x3c/0x80
   entry_SYSCALL_64_after_hwframe+0x46/0xb0

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local de kernel (AV:L/PR:L) que causa NULL pointer dereference y crash. Permite escalada de privilegios (S:C/I:H) y DoS mediante explotación de error en batch carry del iommufd.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-54060",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "f394576eb11dbcd3a740fa41e577b97f0720d26e",
              "lessThan": "176f36a376c417b58d19f79edfce20db9317eaa2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f394576eb11dbcd3a740fa41e577b97f0720d26e",
              "lessThan": "b7c822fa6b7701b17e139f1c562fc24135880ed4",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/iommu/iommufd/pages.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.2"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.2",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.4.8",
              "versionType": "semver",
              "lessThanOrEqual": "6.4.*"
            },
            {
              "status": "unaffected",
              "version": "6.5",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/iommu/iommufd/pages.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-12-24T13:16:07.790",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/176f36a376c417b58d19f79edfce20db9317eaa2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b7c822fa6b7701b17e139f1c562fc24135880ed4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Set end correctly when doing batch carry\n\nEven though the test suite covers this it somehow became obscured that\nthis wasn't working.\n\nThe test iommufd_ioas.mock_domain.access_domain_destory would blow up\nrarely.\n\nend should be set to 1 because this just pushed an item, the carry, to the\npfns list.\n\nSometimes the test would blow up with:\n\n  BUG: kernel NULL pointer dereference, address: 0000000000000000\n  #PF: supervisor read access in kernel mode\n  #PF: error_code(0x0000) - not-present page\n  PGD 0 P4D 0\n  Oops: 0000 [#1] SMP\n  CPU: 5 PID: 584 Comm: iommufd Not tainted 6.5.0-rc1-dirty #1236\n  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n  RIP: 0010:batch_unpin+0xa2/0x100 [iommufd]\n  Code: 17 48 81 fe ff ff 07 00 77 70 48 8b 15 b7 be 97 e2 48 85 d2 74 14 48 8b 14 fa 48 85 d2 74 0b 40 0f b6 f6 48 c1 e6 04 48 01 f2 <48> 8b 3a 48 c1 e0 06 89 ca 48 89 de 48 83 e7 f0 48 01 c7 e8 96 dc\n  RSP: 0018:ffffc90001677a58 EFLAGS: 00010246\n  RAX: 00007f7e2646f000 RBX: 0000000000000000 RCX: 0000000000000001\n  RDX: 0000000000000000 RSI: 00000000fefc4c8d RDI: 0000000000fefc4c\n  RBP: ffffc90001677a80 R08: 0000000000000048 R09: 0000000000000200\n  R10: 0000000000030b98 R11: ffffffff81f3bb40 R12: 0000000000000001\n  R13: ffff888101f75800 R14: ffffc90001677ad0 R15: 00000000000001fe\n  FS:  00007f9323679740(0000) GS:ffff8881ba540000(0000) knlGS:0000000000000000\n  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  CR2: 0000000000000000 CR3: 0000000105ede003 CR4: 00000000003706a0\n  DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n  DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n  Call Trace:\n   <TASK>\n   ? show_regs+0x5c/0x70\n   ? __die+0x1f/0x60\n   ? page_fault_oops+0x15d/0x440\n   ? lock_release+0xbc/0x240\n   ? exc_page_fault+0x4a4/0x970\n   ? asm_exc_page_fault+0x27/0x30\n   ? batch_unpin+0xa2/0x100 [iommufd]\n   ? batch_unpin+0xba/0x100 [iommufd]\n   __iopt_area_unfill_domain+0x198/0x430 [iommufd]\n   ? __mutex_lock+0x8c/0xb80\n   ? __mutex_lock+0x6aa/0xb80\n   ? xa_erase+0x28/0x30\n   ? iopt_table_remove_domain+0x162/0x320 [iommufd]\n   ? lock_release+0xbc/0x240\n   iopt_area_unfill_domain+0xd/0x10 [iommufd]\n   iopt_table_remove_domain+0x195/0x320 [iommufd]\n   iommufd_hw_pagetable_destroy+0xb3/0x110 [iommufd]\n   iommufd_object_destroy_user+0x8e/0xf0 [iommufd]\n   iommufd_device_detach+0xc5/0x140 [iommufd]\n   iommufd_selftest_destroy+0x1f/0x70 [iommufd]\n   iommufd_object_destroy_user+0x8e/0xf0 [iommufd]\n   iommufd_destroy+0x3a/0x50 [iommufd]\n   iommufd_fops_ioctl+0xfb/0x170 [iommufd]\n   __x64_sys_ioctl+0x40d/0x9a0\n   do_syscall_64+0x3c/0x80\n   entry_SYSCALL_64_after_hwframe+0x46/0xb0"
    }
  ],
  "lastModified": "2026-08-04T10:19:26.690",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}