PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-52920 Linux CVE debrief

CVE-2023-52920 is a Linux kernel BPF verifier bug in precision tracking for stack spill/fill history. NVD rates it medium severity (CVSS 5.5) and lists Linux kernel versions before 6.8 as vulnerable, with a local, low-privilege impact profile.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-11-05
Original CVE updated
2026-08-04
Advisory published
2024-11-05
Advisory updated
2026-08-04

Who should care

Linux kernel maintainers, distro security teams, and operators running eBPF/BPF workloads on kernels older than 6.8 should review this CVE, especially where verifier behavior matters for networking, tracing, or other BPF-heavy deployments.

Technical summary

The kernel fix changes how the BPF verifier records instruction history for register spill/fill operations to and from the stack. It extends history tracking so spills and fills are tracked even when they occur through registers other than r10 after copying and adjusting the frame pointer, and it adds per-instruction flags for stack slot index and frame number. The change also resets and reuses the current history-entry pointer to avoid ambiguous backtracking state. In the supplied NVD metadata, the issue is classified as CWE-476 and scored CVSS v3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.

Defensive priority

Medium

Recommended defensive actions

  • Upgrade Linux kernels to a release that includes the fix; NVD marks versions before 6.8 as vulnerable.
  • Check vendor backports and distro kernel advisories, since fixed kernels may retain older version numbers.
  • Prioritize systems that run untrusted or frequently changing BPF programs, or that rely heavily on verifier-sensitive workflows.
  • Validate exposure by confirming whether the relevant kernel build includes the official fix references in its changelog or backport set.

Evidence notes

This debrief is based on the supplied NVD record and the kernel references it cites. The CVE was first published on 2024-11-05T10:15:24.580Z and later modified on 2026-05-17T16:16:13.030Z. NVD lists Linux kernel versions before 6.8 as vulnerable, assigns CVSS v3.1 5.5 MEDIUM, and maps the issue to CWE-476. The supplied kernel description frames the issue as a BPF verifier precision-tracking fix rather than a standalone exploit narrative, so downstream vendor backports should be checked for real-world exposure.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-52920 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-52920

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-52920 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-52920

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/199f0452873741fa4b8d4d88958e929030b2f92b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/41f6f64e6999a837048b1bd13a2f8742964eca6b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Mailing List, Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e4da60feca4d35e1a9b03dc0affa3354f9ff45e4

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ecc2aeeaa08a355d84d3ca9c3d2512399a194f29

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.