CVE-2023-52453: hisi_acc_vfio_pci: Update migration data pointer correctly on saving/resume
In the Linux kernel, the following vulnerability has been resolved:
hisi_acc_vfio_pci: Update migration data pointer correctly on saving/resume
When the optional PRE_COPY support was added to speed up the device
compatibility check, it failed to update the saving/resuming data
pointers based on the fd offset. This results in migration data
corruption and when the device gets started on the destination the
following error is reported in some cases,
[ 478.907684] arm-smmu-v3 arm-smmu-v3.2.auto: event 0x10 received:
[ 478.913691] arm-smmu-v3 arm-smmu-v3.2.auto: 0x0000310200000010
[ 478.919603] arm-smmu-v3 arm-smmu-v3.2.auto: 0x000002088000007f
[ 478.925515] arm-smmu-v3 arm-smmu-v3.2.auto: 0x0000000000000000
[ 478.931425] arm-smmu-v3 arm-smmu-v3.2.auto: 0x0000000000000000
[ 478.947552] hisi_zip 0000:31:00.0: qm_axi_rresp [error status=0x1] found
[ 478.955930] hisi_zip 0000:31:00.0: qm_db_timeout [error status=0x400] found
[ 478.955944] hisi_zip 0000:31:00.0: qm sq doorbell timeout in function 2
Security readout for executives and security teams
Plain-English summary
A Linux kernel flaw can corrupt migration data when certain HiSilicon accelerator devices are moved between virtualized hosts using VFIO pre-copy migration. The destination device may malfunction or become unavailable. Exploitation requires local, low-privileged access; the supplied evidence does not indicate remote exploitation or data disclosure.
Executive priority
Prioritize environments using HiSilicon accelerator passthrough and live device migration. Remediate promptly where that combination exists because failed migrations can disrupt accelerated workloads and corrupt device state. Other Linux systems should first confirm whether the specialized driver and workflow are present, avoiding an unnecessarily broad emergency response.
Technical view
The hisi_acc_vfio_pci driver failed to adjust saving and resuming data pointers using the file-descriptor offset during optional PRE_COPY migration. Corrupted migration state can produce integrity and availability failures when the destination device starts, including SMMU events, accelerator response errors, and queue doorbell timeouts. CVSS 3.1 is 7.1: local access, low complexity, low privileges, high integrity and availability impact.
Likely exposure
Exposure appears limited to affected Linux kernels operating supported HiSilicon accelerator hardware through hisi_acc_vfio_pci and performing VFIO device migration with optional pre-copy behavior. Systems without this hardware, driver, or migration workflow are unlikely to encounter the described path. The supplied affected-version data is ambiguous, so confirm kernel status against vendor advisories and the cited stable fixes.
Exploitation context
The supplied CVSS vector describes a local, low-privileged attack requiring no user interaction. CISA KEV status is false, and the bundle provides no evidence of active exploitation or a public exploit. The documented outcome is migration-state corruption affecting integrity and availability, sometimes visible only when the destination device starts.
Researcher notes
The defect concerns offset-relative migration buffers, not a documented network attack surface. The source bundle names Linux 6.2, 6.6.14, 6.7.2, and 6.8 among affected entries, but its version representation is inconsistent and includes an unexplained โ0.โ Treat commit or distributor backport verification as authoritative. No CWE is supplied.
Mitigation direction
Update to a vendor-supported kernel release containing the applicable cited stable fix.
Check Linux distribution advisories for backport status before relying solely on version numbers.
Avoid VFIO pre-copy migration for affected HiSilicon accelerators until remediation is confirmed.
Restrict local access and authorization for device-migration operations.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve ยท low confidence lookup
CVE-2023-52453 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.