{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2023-53254","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-09-15T14:19:21.849Z","datePublished":"2025-09-15T14:46:24.670Z","dateUpdated":"2026-08-05T09:13:18.284Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T09:13:18.284Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncacheinfo: Fix shared_cpu_map to handle shared caches at different levels\n\nThe cacheinfo sets up the shared_cpu_map by checking whether the caches\nwith the same index are shared between CPUs. However, this will trigger\nslab-out-of-bounds access if the CPUs do not have the same cache hierarchy.\nAnother problem is the mismatched shared_cpu_map when the shared cache does\nnot have the same index between CPUs.\n\nCPU0\tI\tD\tL3\nindex\t0\t1\t2\tx\n\t^\t^\t^\t^\nindex\t0\t1\t2\t3\nCPU1\tI\tD\tL2\tL3\n\nThis patch checks each cache is shared with all caches on other CPUs."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The OOB occurs in cache_shared_cpu_map_setup/remove during local CPU bring-up (cacheinfo_cpu_online, update_siblings_masks/store_cpu_topology, and CPU offline cleanup), not via network packet processing or adjacent-link protocols.\nAC:L - On systems with asymmetric per-CPU cache hierarchies (the SiFive/heterogeneous topology described in the fix), indexing a sibling's smaller info_list with the current CPU's leaf index deterministically causes the slab OOB whenever that CPU comes online; no race or attacker-uncontrollable timing is required.\nPR:L - The OOB runs automatically during normal boot SMP bring-up and kernel-driven CPU hotplug on affected hardware, so a local unprivileged user can be present to leverage the resulting slab corruption without needing to write /sys/devices/system/cpu/*/online as real root.\nUI:N - CPU online/offline and early topology setup invoke the vulnerable path as part of normal kernel operation; no separate victim action such as mounting a filesystem or opening a device is required.\nS:U - The slab out-of-bounds access corrupts kernel heap within the host kernel's security authority and does not cross a VM, IOMMU, or other security boundary.\nC:H - per_cpu_cacheinfo_idx() performs an unbounded slab out-of-bounds read of a full struct cacheinfo from adjacent heap when cache_leaves differ, which per guidance is Confidentiality High rather than a small bounded leak.\nI:H - If cache_leaves_are_shared() accepts the OOB leaf (or on remove after a sibling was recorded), cpumask_set_cpu/cpumask_clear_cpu writes into sib_leaf->shared_cpu_map past the allocated info_list, yielding a heap out-of-bounds write exploitable for integrity compromise.\nA:H - The slab out-of-bounds access can oops/panic the kernel when it hits unmapped or poisoned memory adjacent to the undersized info_list allocation, which is Availability High."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/base/cacheinfo.c"],"versions":[{"version":"246246cbde5e840012f853e27630ebb59f409486","lessThan":"2f588d0345d69a35e451077afed428fd057a5e34","status":"affected","versionType":"git"},{"version":"246246cbde5e840012f853e27630ebb59f409486","lessThan":"dea49f2993f57d8a2df2cacb0bf649ef49b28879","status":"affected","versionType":"git"},{"version":"246246cbde5e840012f853e27630ebb59f409486","lessThan":"198102c9103fc78d8478495971947af77edb05c1","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/base/cacheinfo.c"],"versions":[{"version":"3.19","status":"affected"},{"version":"0","lessThan":"3.19","status":"unaffected","versionType":"semver"},{"version":"6.1.18","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.2.5","lessThanOrEqual":"6.2.*","status":"unaffected","versionType":"semver"},{"version":"6.3","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.19","versionEndExcluding":"6.1.18"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.19","versionEndExcluding":"6.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.19","versionEndExcluding":"6.3"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/2f588d0345d69a35e451077afed428fd057a5e34"},{"url":"https://git.kernel.org/stable/c/dea49f2993f57d8a2df2cacb0bf649ef49b28879"},{"url":"https://git.kernel.org/stable/c/198102c9103fc78d8478495971947af77edb05c1"}],"title":"cacheinfo: Fix shared_cpu_map to handle shared caches at different levels","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":7.1,"attackVector":"LOCAL","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"LOW","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"id":"CVE-2023-53254","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2026-01-14T18:01:14.729698Z"}}}],"problemTypes":[{"descriptions":[{"lang":"en","type":"CWE","cweId":"CWE-125","description":"CWE-125 Out-of-bounds Read"}]}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-01-14T18:02:52.518Z"}}]}}