Kernel panic via misclassified instruction-fetch poison context
Published Sep 18, 2025 · Updated Sep 18, 2025
Denial of service in the Linux x86 machine-check handler allows local users to trigger a kernel panic during AMD Zen poison consumption. The handler leaves the saved CS value at zero when MCG_STATUS lacks EIPV or RIPV, causing severity grading to mistake a user-context instruction-fetch poison error for kernel context. The failure requires an AMD Zen instruction-fetch poison event in a local user's context; the bounded consequence is an unnecessary host crash.
Summary
What happened
Denial of service in the Linux x86 machine-check handler allows local users to trigger a kernel panic during AMD Zen poison consumption. The handler leaves the saved CS value at zero when MCG_STATUS lacks EIPV or RIPV, causing severity grading to mistake a user-context instruction-fetch poison error for kernel context. The failure requires an AMD Zen instruction-fetch poison event in a local user's context; the bounded consequence is an unnecessary host crash.
The record
- CVE
- CVE-2023-53438
- Published
- Sep 18, 2025
- Updated
- Sep 18, 2025
- Vendor
- The Linux Kernel Organization
- Product
- Linux
- Classifications
- T1499.004
- Attack vector
- local
- Privileges
- authenticated
Timeline
How it unfolded
- Sep 18, 2025CVE publishedPublication date reported by the CVE source.
- Sep 18, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <2e01bdf7203c383e9d8489d9f963c52d6c81e4db
- Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <4240e2ebe67941ce2c4f5c866c3af4b5ac7a0c67
- Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <6eac3965901489ae114a664a78cd2d1415d1af5c
- Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e6e6a5f50f58fadec397b23064b7e4830292863d
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo