{"id":"DEBIAN-CVE-2023-53583","details":"In the Linux kernel, the following vulnerability has been resolved:  perf: RISC-V: Remove PERF_HES_STOPPED flag checking in riscv_pmu_start()  Since commit 096b52fd2bb4 (\"perf: RISC-V: throttle perf events\") the perf_sample_event_took() function was added to report time spent in overflow interrupts. If the interrupt takes too long, the perf framework will lower the sysctl_perf_event_sample_rate and max_samples_per_tick. When hwc-\u003einterrupts is larger than max_samples_per_tick, the hwc-\u003einterrupts will be set to MAX_INTERRUPTS, and events will be throttled within the __perf_event_account_interrupt() function.  However, the RISC-V PMU driver doesn't call riscv_pmu_stop() to update the PERF_HES_STOPPED flag after perf_event_overflow() in pmu_sbi_ovf_handler() function to avoid throttling. When the perf framework unthrottled the event in the timer interrupt handler, it triggers riscv_pmu_start() function and causes a WARN_ON_ONCE() warning, as shown below:   ------------[ cut here ]------------  WARNING: CPU: 0 PID: 240 at drivers/perf/riscv_pmu.c:184 riscv_pmu_start+0x7c/0x8e  Modules linked in:  CPU: 0 PID: 240 Comm: ls Not tainted 6.4-rc4-g19d0788e9ef2 #1  Hardware name: SiFive (DT)  epc : riscv_pmu_start+0x7c/0x8e   ra : riscv_pmu_start+0x28/0x8e  epc : ffffffff80aef864 ra : ffffffff80aef810 sp : ffff8f80004db6f0   gp : ffffffff81c83750 tp : ffffaf80069f9bc0 t0 : ffff8f80004db6c0   t1 : 0000000000000000 t2 : 000000000000001f s0 : ffff8f80004db720   s1 : ffffaf8008ca1068 a0 : 0000ffffffffffff a1 : 0000000000000000   a2 : 0000000000000001 a3 : 0000000000000870 a4 : 0000000000000000   a5 : 0000000000000000 a6 : 0000000000000840 a7 : 0000000000000030   s2 : 0000000000000000 s3 : ffffaf8005165800 s4 : ffffaf800424da00   s5 : ffffffffffffffff s6 : ffffffff81cc7590 s7 : 0000000000000000   s8 : 0000000000000006 s9 : 0000000000000001 s10: ffffaf807efbc340   s11: ffffaf807efbbf00 t3 : ffffaf8006a16028 t4 : 00000000dbfbb796   t5 : 0000000700000000 t6 : ffffaf8005269870  status: 0000000200000100 badaddr: 0000000000000000 cause: 0000000000000003  [\u003cffffffff80aef864\u003e] riscv_pmu_start+0x7c/0x8e  [\u003cffffffff80185b56\u003e] perf_adjust_freq_unthr_context+0x15e/0x174  [\u003cffffffff80188642\u003e] perf_event_task_tick+0x88/0x9c  [\u003cffffffff800626a8\u003e] scheduler_tick+0xfe/0x27c  [\u003cffffffff800b5640\u003e] update_process_times+0x9a/0xba  [\u003cffffffff800c5bd4\u003e] tick_sched_handle+0x32/0x66  [\u003cffffffff800c5e0c\u003e] tick_sched_timer+0x64/0xb0  [\u003cffffffff800b5e50\u003e] __hrtimer_run_queues+0x156/0x2f4  [\u003cffffffff800b6bdc\u003e] hrtimer_interrupt+0xe2/0x1fe  [\u003cffffffff80acc9e8\u003e] riscv_timer_interrupt+0x38/0x42  [\u003cffffffff80090a16\u003e] handle_percpu_devid_irq+0x90/0x1d2  [\u003cffffffff8008a9f4\u003e] generic_handle_domain_irq+0x28/0x36  After referring other PMU drivers like Arm, Loongarch, Csky, and Mips, they don't call *_pmu_stop() to update with PERF_HES_STOPPED flag after perf_event_overflow() function nor do they add PERF_HES_STOPPED flag checking in *_pmu_start() which don't cause this warning.  Thus, it's recommended to remove this unnecessary check in riscv_pmu_start() function to prevent this warning.","modified":"2026-09-15T09:03:01.796772481Z","published":"2025-10-04T16:15:54.090Z","upstream":["CVE-2023-53583"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-53583"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.52-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53583.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53583.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53583.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}