CVE-2023-52914
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2023-52914 affects the Linux kernel's io_uring subsystem. The vulnerability was discovered in the poll request handling mechanism where a ready poll request that cannot complete inline may lose access completely, leading to a request leak. This issue was identified and resolved in January 2023, affecting Linux kernel versions from 6.0 up to (excluding) 6.1.7, and specific release candidates 6.2-rc1, 6.2-rc2, and 6.2-rc3 (NVD).

Technical details

The vulnerability stems from a flaw in the io_uring poll request handling where if a ready poll request cannot complete inline, it fails to add the request to the hash table. This oversight can result in completely losing access to the request. The issue has been assigned a CVSS v3.1 base score of 5.5 (Medium) with vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. The vulnerability is classified as CWE-401: Missing Release of Memory after Effective Lifetime (NVD).

Impact

The primary impact of this vulnerability is a memory leak through request leakage, which can eventually lead to stalling of the ring exit process. This affects system availability by potentially causing resource exhaustion and system performance degradation (NVD).

Mitigation and workarounds

The issue has been fixed by adding proper hash table handling for ready poll requests that cannot complete inline. The fix involves adding a new function iopolladd_hash() to ensure proper request tracking. Users should upgrade to Linux kernel version 6.1.7 or later, or apply the patch that fixes this issue (Kernel Patch).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40289N/AN/A
  • Linux DebianLinux Debian
  • linux
NoYesDec 06, 2025
CVE-2025-40288N/AN/A
  • Linux DebianLinux Debian
  • linux
NoYesDec 06, 2025
CVE-2025-40287N/AN/A
  • Linux DebianLinux Debian
  • linux
NoYesDec 06, 2025
CVE-2025-40286N/AN/A
  • Linux DebianLinux Debian
  • linux
NoYesDec 06, 2025
CVE-2025-40285N/AN/A
  • Linux DebianLinux Debian
  • linux
NoYesDec 06, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management