CVE-2023-53007

Source
https://cve.org/CVERecord?id=CVE-2023-53007
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53007.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-53007
Downstream
Related
Published
2025-03-27T16:43:38.102Z
Modified
2026-04-02T09:43:33.665607Z
Summary
tracing: Make sure trace_printk() can output as soon as it can be used
Details

In the Linux kernel, the following vulnerability has been resolved:

tracing: Make sure trace_printk() can output as soon as it can be used

Currently traceprintk() can be used as soon as earlytraceinit() is called from startkernel(). But if a crash happens, and "ftracedumpon_oops" is set on the kernel command line, all you get will be:

[ 0.456075] <idle>-0 0dN.2. 347519us : Unknown type 6 [ 0.456075] <idle>-0 0dN.2. 353141us : Unknown type 6 [ 0.456075] <idle>-0 0dN.2. 358684us : Unknown type 6

This is because the traceprintk() event (type 6) hasn't been registered yet. That gets done via an earlyinitcall(), which may be early, but not early enough.

Instead of registering the traceprintk() event (and other ftrace events, which are not trace events) via an earlyinitcall(), have them registered at the same time that traceprintk() can be used. This way, if there is a crash before earlyinitcall(), then the trace_printk()s will actually be useful.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53007.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e725c731e3bb1e892e7b564c945b121cb41d1087
Fixed
f97eb0ab066133483a65c93eb894748de2f6b598
Fixed
b94d7c7654356860dd7719120c7d15ba38b6162a
Fixed
76b2390fdc80c0a8300e5da5b6b62d201b6fe9ce
Fixed
de3930a4883ddad2244efd6d349013294c62c75c
Fixed
b0af180514edea6c83dc9a299d9f383009c99f25
Fixed
198c83963f6335ca6d690cff067679560f2a3a22
Fixed
3bb06eb6e9acf7c4a3e1b5bc87aed398ff8e2253

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53007.json"