CVE-2023-53319
Linux Kernel vulnerability analysis and mitigation

Overview

In the Linux kernel, a vulnerability (CVE-2023-53319) has been identified related to the synchronization between finalize_pkvm() and kvm_arm_init() initcalls in the ARM64 KVM implementation. The issue was discovered when finalize_pkvm() continues execution even if kvm_arm_init() fails, leading to warnings on all CPUs and eventually resulting in a HYP panic (NVD).

Technical details

The vulnerability occurs in the ARM64 KVM implementation where there is no proper synchronization between finalize_pkvm() and kvm_arm_init() initcalls. When kvm_arm_init() fails, finalize_pkvm() continues execution regardless, which triggers warnings on all CPUs with messages indicating 'Failed to init hyp memory protection' and 'error initializing Hyp mode: -22'. This eventually leads to a kernel panic with HYP panic messages (NVD).

Impact

The vulnerability can result in system instability and kernel panic on affected ARM64 systems running KVM virtualization. This can lead to system crashes and potential service disruption (NVD).

Mitigation and workarounds

The fix involves implementing proper checking for the successful initialization of kvm_arm_init() in finalize_pkvm() before proceeding further. This ensures that the finalization process only continues when the initialization has completed successfully (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-68753HIGH7.8
  • Linux KernelLinux Kernel
  • linux-oem-6.14
NoYesJan 05, 2026
CVE-2025-68756HIGH7.1
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug
NoYesJan 05, 2026
CVE-2025-68764MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-rt-64k-core
NoYesJan 05, 2026
CVE-2025-68758MEDIUM5.5
  • Linux KernelLinux Kernel
  • linux-nvidia-tegra-5.15
NoYesJan 05, 2026
CVE-2025-68762N/AN/A
  • Linux KernelLinux Kernel
  • linux-aws-fips
NoYesJan 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management