{"id":"DEBIAN-CVE-2023-52928","details":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Skip invalid kfunc call in backtrack_insn  The verifier skips invalid kfunc call in check_kfunc_call(), which would be captured in fixup_kfunc_call() if such insn is not eliminated by dead code elimination. However, this can lead to the following warning in backtrack_insn(), also see [1]:    ------------[ cut here ]------------   verifier backtracking bug   WARNING: CPU: 6 PID: 8646 at kernel/bpf/verifier.c:2756 backtrack_insn   kernel/bpf/verifier.c:2756 \t__mark_chain_precision kernel/bpf/verifier.c:3065 \tmark_chain_precision kernel/bpf/verifier.c:3165 \tadjust_reg_min_max_vals kernel/bpf/verifier.c:10715 \tcheck_alu_op kernel/bpf/verifier.c:10928 \tdo_check kernel/bpf/verifier.c:13821 [inline] \tdo_check_common kernel/bpf/verifier.c:16289   [...]  So make backtracking conservative with this by returning ENOTSUPP.    [1] https://lore.kernel.org/bpf/CACkBjsaXNceR8ZjkLG=dT3P=4A8SBsg0Z5h5PWLryF5=ghKq=g@mail.gmail.com/","modified":"2026-09-15T09:02:49.319886046Z","published":"2025-03-27T17:15:42.230Z","upstream":["CVE-2023-52928"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-52928"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-52928.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-52928.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-52928.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}