{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.11-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.11-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.11-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  riscv: kprobe: Fixup kernel panic when probing an illegal position  The kernel would panic when probed for an illegal position. eg:  (CONFIG_RISCV_ISA_C=n)  echo 'p:hello kernel_clone+0x16 a0=%a0' \u003e\u003e kprobe_events echo 1 \u003e events/kprobes/hello/enable cat trace  Kernel panic - not syncing: stack-protector: Kernel stack is corrupted in: __do_sys_newfstatat+0xb8/0xb8 CPU: 0 PID: 111 Comm: sh Not tainted 6.2.0-rc1-00027-g2d398fe49a4d #490 Hardware name: riscv-virtio,qemu (DT) Call Trace: [\u003cffffffff80007268\u003e] dump_backtrace+0x38/0x48 [\u003cffffffff80c5e83c\u003e] show_stack+0x50/0x68 [\u003cffffffff80c6da28\u003e] dump_stack_lvl+0x60/0x84 [\u003cffffffff80c6da6c\u003e] dump_stack+0x20/0x30 [\u003cffffffff80c5ecf4\u003e] panic+0x160/0x374 [\u003cffffffff80c6db94\u003e] generic_handle_arch_irq+0x0/0xa8 [\u003cffffffff802deeb0\u003e] sys_newstat+0x0/0x30 [\u003cffffffff800158c0\u003e] sys_clone+0x20/0x30 [\u003cffffffff800039e8\u003e] ret_from_syscall+0x0/0x4 ---[ end Kernel panic - not syncing: stack-protector: Kernel stack is corrupted in: __do_sys_newfstatat+0xb8/0xb8 ]---  That is because the kprobe's ebreak instruction broke the kernel's original code. The user should guarantee the correction of the probe position, but it couldn't make the kernel panic.  This patch adds arch_check_kprobe in arch_prepare_kprobe to prevent an illegal position (Such as the middle of an instruction).",
  "id": "DEBIAN-CVE-2023-52978",
  "modified": "2026-09-15T08:47:33.468671199Z",
  "published": "2025-03-27T17:15:44.923Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2023-52978"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2023-52978"
  ]
}