CVE-2023-52831 is a vulnerability in the Linux kernel related to CPU hotplug functionality. It allows a local attacker to cause a denial of service (system crash) by attempting to offline the last non-isolated CPU on systems configured with "isolcpus=". This vulnerability has a CVSS score of 5.5 (Medium) due to its local attack vector and high impact on availability, with low attack complexity and required privileges. There is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.1.53, < 6.1.64CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.4.16, < 6.5CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.5.3, < 6.5.13CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
< 6.1.64CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.5.13CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.