Bug 1216255 (CVE-2023-40791) - VUL-0: CVE-2023-40791: kernel: extract_user_to_sg in lib/scatterlist.c in the Linux kernel before 6.4.12 fails to unpin pages in a certain situation, as demonstrated by a WARNING for try_grab_page.
Summary: VUL-0: CVE-2023-40791: kernel: extract_user_to_sg in lib/scatterlist.c in the...
Status: RESOLVED FIXED
Alias: CVE-2023-40791
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/381907/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-10-16 06:57 UTC by SMASH SMASH
Modified: 2023-10-16 09:12 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2023-10-16 06:57:50 UTC
extract_user_to_sg in lib/scatterlist.c in the Linux kernel before 6.4.12 fails to unpin pages in a certain situation, as demonstrated by a WARNING for try_grab_page.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-40791
Comment 1 Gabriele Sonnu 2023-10-16 07:00:00 UTC
Offending commit (018584697533) is included in SLE15-SP6 and stable branches, that also contain the fixing commit (f443fd5af5dbd531f880d3645d5dd36976cf087f). Nothing to do, closing.