LiveActive security incident?Get immediate response
CVE Record

CVE-2023-52453: hisi_acc_vfio_pci: Update migration data pointer correctly on saving/resume

In the Linux kernel, the following vulnerability has been resolved: hisi_acc_vfio_pci: Update migration data pointer correctly on saving/resume When the optional PRE_COPY support was added to speed up the device compatibility check, it failed to update the saving/resuming data pointers based on the fd offset. This results in migration data corruption and when the device gets started on the destination the following error is reported in some cases, [ 478.907684] arm-smmu-v3 arm-smmu-v3.2.auto: event 0x10 received: [ 478.913691] arm-smmu-v3 arm-smmu-v3.2.auto: 0x0000310200000010 [ 478.919603] arm-smmu-v3 arm-smmu-v3.2.auto: 0x000002088000007f [ 478.925515] arm-smmu-v3 arm-smmu-v3.2.auto: 0x0000000000000000 [ 478.931425] arm-smmu-v3 arm-smmu-v3.2.auto: 0x0000000000000000 [ 478.947552] hisi_zip 0000:31:00.0: qm_axi_rresp [error status=0x1] found [ 478.955930] hisi_zip 0000:31:00.0: qm_db_timeout [error status=0x400] found [ 478.955944] hisi_zip 0000:31:00.0: qm sq doorbell timeout in function 2

HighCVSS 7.1Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

A Linux kernel flaw can corrupt migration data when certain HiSilicon accelerator devices are moved between virtualized hosts using VFIO pre-copy migration. The destination device may malfunction or become unavailable. Exploitation requires local, low-privileged access; the supplied evidence does not indicate remote exploitation or data disclosure.

Executive priority

Prioritize environments using HiSilicon accelerator passthrough and live device migration. Remediate promptly where that combination exists because failed migrations can disrupt accelerated workloads and corrupt device state. Other Linux systems should first confirm whether the specialized driver and workflow are present, avoiding an unnecessarily broad emergency response.

Technical view

The hisi_acc_vfio_pci driver failed to adjust saving and resuming data pointers using the file-descriptor offset during optional PRE_COPY migration. Corrupted migration state can produce integrity and availability failures when the destination device starts, including SMMU events, accelerator response errors, and queue doorbell timeouts. CVSS 3.1 is 7.1: local access, low complexity, low privileges, high integrity and availability impact.

Likely exposure

Exposure appears limited to affected Linux kernels operating supported HiSilicon accelerator hardware through hisi_acc_vfio_pci and performing VFIO device migration with optional pre-copy behavior. Systems without this hardware, driver, or migration workflow are unlikely to encounter the described path. The supplied affected-version data is ambiguous, so confirm kernel status against vendor advisories and the cited stable fixes.

Exploitation context

The supplied CVSS vector describes a local, low-privileged attack requiring no user interaction. CISA KEV status is false, and the bundle provides no evidence of active exploitation or a public exploit. The documented outcome is migration-state corruption affecting integrity and availability, sometimes visible only when the destination device starts.

Researcher notes

The defect concerns offset-relative migration buffers, not a documented network attack surface. The source bundle names Linux 6.2, 6.6.14, 6.7.2, and 6.8 among affected entries, but its version representation is inconsistent and includes an unexplained โ€œ0.โ€ Treat commit or distributor backport verification as authoritative. No CWE is supplied.

Mitigation direction

  • Update to a vendor-supported kernel release containing the applicable cited stable fix.
  • Check Linux distribution advisories for backport status before relying solely on version numbers.
  • Avoid VFIO pre-copy migration for affected HiSilicon accelerators until remediation is confirmed.
  • Restrict local access and authorization for device-migration operations.

Validation and detection

  • Inventory kernels, HiSilicon accelerator hardware, hisi_acc_vfio_pci usage, and VFIO migration workflows.
  • Compare deployed kernel source or vendor changelogs with the three cited stable fixes.
  • Review destination-host logs for SMMU events, qm_axi_rresp errors, and queue doorbell timeouts.
  • Test authorized device migration in a controlled environment after updating, confirming destination-device health.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve ยท low confidence lookup

CVE-2023-52453 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.1 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

2CVSS vectors
3Timeline events
2ADP providers
4Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

CVSS vector scores

2 official scores

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.1CVSS 3.1HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H1.85.2Linux
5.5CVSS 3.1MediumCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H1.83.6CISA-ADP

Vulnerability scoring details

Base CVSS 3.1 score

7.1High
CVSS 3.1 vector shape for CVE-2023-52453Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
cvssV3_1other:ssvc
CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinuxd9a871e4a143047d1d84a606772af319f11516f9, d9a871e4a143047d1d84a606772af319f11516f9, d9a871e4a143047d1d84a606772af319f11516f9unaffected
LinuxLinux6.2, 0, 6.6.14, 6.7.2, 6.8affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.