CVE-2023-52993
Linux Kernel vulnerability analysis and mitigation

Overview

A vulnerability in the Linux kernel (CVE-2023-52993) was identified and resolved, involving the x86/i8259 legacy PIC interrupts. The issue was discovered when crash-kernel failures occurred approximately 50% of the time after triggering a crash. This vulnerability was publicly disclosed on March 27, 2025 (NVD).

Technical details

The vulnerability stems from a NULL pointer dereference in the periodic tick code. The issue occurs because the legacy timer interrupt (IRQ0) is resent in software during soft interrupt (tasklet) context. In this context, getirqregs() returns NULL, leading to the NULL pointer dereference. The root cause was identified as a spurious APIC interrupt on the IRQ0 vector that triggers a resend when the legacy timer interrupt is enabled. The core issue was that legacy PIC interrupts, which are level triggered, were not properly marked with the IRQ_LEVEL flag, causing incorrect handling in the core code (NVD).

Impact

The vulnerability causes system instability and potential crashes, specifically affecting systems using legacy PIC interrupts. When triggered, it causes the crash-kernel to fail to boot approximately 50% of the time, impacting system reliability and availability (NVD).

Mitigation and workarounds

The fix involves ensuring that IRQ_LEVEL is properly set when legacy PCI interrupts are set up. This correction prevents the incorrect software resend of level-triggered interrupts (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40205HIGH7.8
  • Linux KernelLinux Kernel
  • linux-gcp-5.4
NoYesNov 12, 2025
CVE-2025-40211HIGH7.1
  • Linux KernelLinux Kernel
  • linux-gcp-6.8
NoYesNov 21, 2025
CVE-2025-40206MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-modules-extra
NoYesNov 12, 2025
CVE-2025-40210MEDIUM5.1
  • Linux KernelLinux Kernel
  • kernel-rt-64k-modules
NoYesNov 21, 2025
CVE-2025-40212N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-6.14
NoYesNov 24, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management