CVE-2023-54137 Details
Description
In the Linux kernel, the following vulnerability has been resolved: vfio/type1: fix cap_migration information leak Fix an information leak where an uninitialized hole in struct vfio_iommu_type1_info_cap_migration on the stack is exposed to userspace. The definition of struct vfio_iommu_type1_info_cap_migration contains a hole as shown in this pahole(1) output: struct vfio_iommu_type1_info_cap_migration { struct vfio_info_cap_header header; /* 0 8 */ __u32 flags; /* 8 4 */ /* XXX 4 bytes hole, try to pack */ __u64 pgsize_bitmap; /* 16 8 */ __u64 max_dirty_bitmap_size; /* 24 8 */ /* size: 32, cachelines: 1, members: 4 */ /* sum members: 28, holes: 1, sum holes: 4 */ /* last cacheline: 32 bytes */ }; The cap_mig variable is filled in without initializing the hole: static int vfio_iommu_migration_build_caps(struct vfio_iommu *iommu, struct vfio_info_cap *caps) { struct vfio_iommu_type1_info_cap_migration cap_mig; cap_mig.header.id = VFIO_IOMMU_TYPE1_INFO_CAP_MIGRATION; cap_mig.header.version = 1; cap_mig.flags = 0; /* support minimum pgsize */ cap_mig.pgsize_bitmap = (size_t)1 << __ffs(iommu->pgsize_bitmap); cap_mig.max_dirty_bitmap_size = DIRTY_BITMAP_SIZE_MAX; return vfio_info_add_capability(caps, &cap_mig.header, sizeof(cap_mig)); } The structure is then copied to a temporary location on the heap. At this point it's already too late and ioctl(VFIO_IOMMU_GET_INFO) copies it to userspace later: int vfio_info_add_capability(struct vfio_info_cap *caps, struct vfio_info_cap_header *cap, size_t size) { struct vfio_info_cap_header *header; header = vfio_info_cap_add(caps, size, cap->id, cap->version); if (IS_ERR(header)) return PTR_ERR(header); memcpy(header + 1, cap + 1, size - sizeof(*header)); return 0; } This issue was found by code inspection.
A vulnerability in the Linux kernel's VFIO (Virtual Function I/O) subsystem has been identified, specifically within the type1 IOMMU (Input/Output Memory Management Unit) driver. This vulnerability involves an information leak where an uninitialized portion of a data structure, related to migration capabilities, is exposed to userspace. The issue arises because the structure, 'vfio_iommu_type1_info_cap_migration', contains a gap that is not properly initialized before being sent to userspace, potentially allowing for the disclosure of sensitive information.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been patched. The specific commit that addresses this issue is '13fd667db999bffb557c5de7adb3c14f1713dd51', which is available in the Linux kernel stable tree.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/13fd667db999bffb557c5de7adb3c14f1713dd51 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/1b5feb8497cdb5b9962db2700814bffbc030fb4a | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/ad83d83dd891244de0d07678b257dc976db7c132 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/cbac29a1caa49a34e131394e1f4d924a76d8b0c9 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/cd24e2a60af633f157d7e59c0a6dba64f131c0b1 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/f6f300ecc196d243c02adeb9ee0c62c677c24bfb | kernel.org | Source CodeVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Linux kernel | All versions |
CPE
Remediation
| |
| vfio_iommu_type1 | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Dec 24, 2025 | New CVE Received | kernel.org |
Volerion