Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2023-53070

5.5 · MEDIUM
Published May 2, 2025 linux CWE-252 EPSS 0.19% (8th pctl)

Overview

CVE-2023-53070 is a medium-severity vulnerability affecting linux linux_kernel. It was published on May 2, 2025 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

ACPI: PPTT: Fix to avoid sleep in the atomic context when PPTT is absent

Commit 0c80f9e165f8 ("ACPI: PPTT: Leave the table mapped for the runtime usage")

enabled to map PPTT once on the first invocation of acpi_get_pptt() and

never unmapped the same allowing it to be used at runtime with out the

hassle of mapping and unmapping the table. This was needed to fetch LLC

information from the PPTT in the cpuhotplug path which is executed in

the atomic context as the acpi_get_table() might sleep waiting for a

mutex.

However it missed to handle the case when there is no PPTT on the system

which results in acpi_get_pptt() being called from all the secondary

CPUs attempting to fetch the LLC information in the atomic context

without knowing the absence of PPTT resulting in the splat like below:

| BUG: sleeping function called from invalid context at kernel/locking/semaphore.c:164

| in_atomic(): 1, irqs_disabled(): 1, non_bl

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 5.19.4, < 6.1.21 Affected

Frequently Asked Questions

What is CVE-2023-53070?

CVE-2023-53070 is a medium-severity vulnerability affecting linux linux_kernel. It was published on May 2, 2025 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

How severe is CVE-2023-53070?

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2023-53070?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2023-53070?

CyberStrike's AI-powered security agents can automatically detect CVE-2023-53070 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.