A deadlock flaw was found in the Linux kernel’s BPF subsystem. This flaw allows a local user to potentially crash the system.
Workaround:
The product contains multiple threads or executable segments that are waiting for each other to release a necessary lock, resulting in deadlock.
The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.
Link | Tags |
---|---|
https://access.redhat.com/security/cve/CVE-2023-0160 | mitigation third party advisory vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=2159764 | third party advisory issue tracking |
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ed17aa92dc56 | patch mailing list |
https://lore.kernel.org/all/CABcoxUayum5oOqFMMqAeWuS8+EzojquSOSyDA3J_2omY=2EeAg@mail.gmail.com/ | vendor advisory mailing list exploit |