{"id":"DEBIAN-CVE-2023-53169","details":"In the Linux kernel, the following vulnerability has been resolved:  x86/resctrl: Clear staged_config[] before and after it is used  As a temporary storage, staged_config[] in rdt_domain should be cleared before and after it is used. The stale value in staged_config[] could cause an MSR access error.  Here is a reproducer on a system with 16 usable CLOSIDs for a 15-way L3 Cache (MBA should be disabled if the number of CLOSIDs for MB is less than 16.) : \tmount -t resctrl resctrl -o cdp /sys/fs/resctrl \tmkdir /sys/fs/resctrl/p{1..7} \tumount /sys/fs/resctrl/ \tmount -t resctrl resctrl /sys/fs/resctrl \tmkdir /sys/fs/resctrl/p{1..8}  An error occurs when creating resource group named p8:     unchecked MSR access error: WRMSR to 0xca0 (tried to write 0x00000000000007ff) at rIP: 0xffffffff82249142 (cat_wrmsr+0x32/0x60)     Call Trace:      \u003cIRQ\u003e      __flush_smp_call_function_queue+0x11d/0x170      __sysvec_call_function+0x24/0xd0      sysvec_call_function+0x89/0xc0      \u003c/IRQ\u003e      \u003cTASK\u003e      asm_sysvec_call_function+0x16/0x20  When creating a new resource control group, hardware will be configured by the following process:     rdtgroup_mkdir()       rdtgroup_mkdir_ctrl_mon()         rdtgroup_init_alloc()           resctrl_arch_update_domains()  resctrl_arch_update_domains() iterates and updates all resctrl_conf_type whose have_new_ctrl is true. Since staged_config[] holds the same values as when CDP was enabled, it will continue to update the CDP_CODE and CDP_DATA configurations. When group p8 is created, get_config_index() called in resctrl_arch_update_domains() will return 16 and 17 as the CLOSIDs for CDP_CODE and CDP_DATA, which will be translated to an invalid register - 0xca0 in this scenario.  Fix it by clearing staged_config[] before and after it is used.  [reinette: re-order commit tags]","modified":"2026-09-15T09:02:53.223626671Z","published":"2025-09-15T14:15:38.693Z","upstream":["CVE-2023-53169"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-53169"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.25-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53169.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.25-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53169.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.25-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53169.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}