CVE-2023-53007: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: tracing: Make sure trace_printk() can output as soon as it can be used Currently trace_printk() can be used as soon as early_trace_init() is called from start_kernel(). But if a crash happens, and "ftrace_dump_on_oops" is set on the kernel command line, all you get will be: [ 0.456075] <idle>-0 0dN.2. 347519us : Unknown type 6 [ 0.456075] <idle>-0 0dN.2. 353141us : Unknown type 6 [ 0.456075] <idle>-0 0dN.2. 358684us : Unknown type 6 This is because the trace_printk() event (type 6) hasn't been registered yet. That gets done via an early_initcall(), which may be early, but not early enough. Instead of registering the trace_printk() event (and other ftrace events, which are not trace events) via an early_initcall(), have them registered at the same time that trace_printk() can be used. This way, if there is a crash before early_initcall(), then the trace_printk()s will actually be useful.

Affected products

  • Linux Linux Kernel: from 4.12, before 4.14.305 (fixed in 4.14.305); from 4.15, before 4.19.272 (fixed in 4.19.272); from 4.20, before 5.4.231 (fixed in 5.4.231); from 5.5, before 5.10.166 (fixed in 5.10.166); from 5.11, before 5.15.91 (fixed in 5.15.91); from 5.16, before 6.1.9 (fixed in 6.1.9); …

Published 2025-03-27. Last modified 2026-06-17.