CVE-2023-52619 is a moderate-severity denial-of-service flaw in the Linux kernel's pstore/ram subsystem. Systems configured with an odd number of CPU cores can calculate an odd zone size, producing unaligned alternate-zone virtual addresses and potentially crashing the kernel when those addresses are accessed. Exploitation requires a local, authenticated low-privileged attacker and no user interaction; Red Hat rates the issue CVSS 3.1 5.5.
The upstream fix aligns the zone size downward with ALIGN_DOWN() and is included in Linux stable releases 4.19.307, 5.4.269, 5.10.210, 5.15.149, 6.1.77, 6.6.16, 6.7.4, and 6.8 and later. Red Hat has issued corrected kernel packages for affected RHEL 8 and RHEL 9 streams, including specified EUS and real-time kernels, and advises prompt updates because no practical mitigation is available; unsupported RHEL 6 and 7 kernels should be presumed vulnerable.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:5101 for the RHEL 8 kernel and RHSA-2024:5102 for the RHEL 8 kernel-rt, fixing CVE-2023-52619.
Red Hat released RHSA-2024:10771, RHSA-2024:10772, and RHSA-2024:10773, fixing CVE-2023-52619 in the RHEL 9.4 EUS kernel and RHEL 9.2 EUS kernel and kernel-rt streams.
Red Hat released RHSA-2024:9315 to fix CVE-2023-52619 in the RHEL 9 kernel.
Red Hat released RHSA-2024:6206, fixing CVE-2023-52619 in the RHEL 8.8 Extended Update Support kernel.
The Linux kernel CVE team documented CVE-2023-52619 in pstore/ram, where an odd CPU count can create misaligned zone addresses and crash the kernel. Fixes use ALIGN_DOWN() to make zone sizes even and were incorporated into stable versions 4.19.307, 5.4.269, 5.10.210, 5.15.149, 6.1.77, 6.6.16, 6.7.4, and 6.8.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.