{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.25-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.25-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.25-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  x86/resctrl: Clear staged_config[] before and after it is used  As a temporary storage, staged_config[] in rdt_domain should be cleared before and after it is used. The stale value in staged_config[] could cause an MSR access error.  Here is a reproducer on a system with 16 usable CLOSIDs for a 15-way L3 Cache (MBA should be disabled if the number of CLOSIDs for MB is less than 16.) : \tmount -t resctrl resctrl -o cdp /sys/fs/resctrl \tmkdir /sys/fs/resctrl/p{1..7} \tumount /sys/fs/resctrl/ \tmount -t resctrl resctrl /sys/fs/resctrl \tmkdir /sys/fs/resctrl/p{1..8}  An error occurs when creating resource group named p8:     unchecked MSR access error: WRMSR to 0xca0 (tried to write 0x00000000000007ff) at rIP: 0xffffffff82249142 (cat_wrmsr+0x32/0x60)     Call Trace:      \u003cIRQ\u003e      __flush_smp_call_function_queue+0x11d/0x170      __sysvec_call_function+0x24/0xd0      sysvec_call_function+0x89/0xc0      \u003c/IRQ\u003e      \u003cTASK\u003e      asm_sysvec_call_function+0x16/0x20  When creating a new resource control group, hardware will be configured by the following process:     rdtgroup_mkdir()       rdtgroup_mkdir_ctrl_mon()         rdtgroup_init_alloc()           resctrl_arch_update_domains()  resctrl_arch_update_domains() iterates and updates all resctrl_conf_type whose have_new_ctrl is true. Since staged_config[] holds the same values as when CDP was enabled, it will continue to update the CDP_CODE and CDP_DATA configurations. When group p8 is created, get_config_index() called in resctrl_arch_update_domains() will return 16 and 17 as the CLOSIDs for CDP_CODE and CDP_DATA, which will be translated to an invalid register - 0xca0 in this scenario.  Fix it by clearing staged_config[] before and after it is used.  [reinette: re-order commit tags]",
  "id": "DEBIAN-CVE-2023-53169",
  "modified": "2026-09-15T08:47:48.412368605Z",
  "published": "2025-09-15T14:15:38.693Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2023-53169"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2023-53169"
  ]
}