CVE-2023-52774
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-52774 affects the Linux kernel's s390/dasd component, specifically the device queue access mechanism. The vulnerability was discovered in October 2023 and involves unprotected concurrent access to the device queue in the dasd_profile_start() function (Kernel Commit).

Technical details

The vulnerability exists in the dasd_profile_start() function where requests on the device queue are counted without proper synchronization. When there is high parallel I/O activity, especially with alias devices enabled, the device queue can change during access, potentially leading to incorrect pointer accesses. The issue stems from a lack of proper locking mechanisms when accessing the queue (Kernel Commit).

Impact

In the worst-case scenario, this vulnerability can lead to a kernel panic due to incorrect pointer accesses during concurrent queue operations. This is particularly problematic in environments with high parallel I/O operations and when alias devices are enabled (Kernel Commit).

Exploitability

The vulnerability requires specific conditions to be exploited, particularly high parallel I/O operations with alias devices enabled. The issue is triggered during normal system operation rather than through malicious input (Kernel Commit).

Mitigation and workarounds

The issue has been fixed by implementing proper locking mechanisms. The fix involves taking the device lock before accessing the queue and counting requests, and optimizing the profile data pointer check to avoid unnecessary locking in hot paths. The patch was submitted by Jan Höppner and reviewed by Stefan Haberland (Kernel Commit).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74732NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-firmware
NoYesAug 22, 2026
CVE-2026-74730NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel
NoYesAug 22, 2026
CVE-2026-74726NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-debug-modules
NoYesAug 22, 2026
CVE-2026-74719NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-modules-partner
NoYesAug 22, 2026
CVE-2026-74717NONEN/A
  • Linux Kernel logoLinux Kernel
  • rtla
NoYesAug 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management