{"id":"DEBIAN-CVE-2023-53656","details":"In the Linux kernel, the following vulnerability has been resolved:  drivers/perf: hisi: Don't migrate perf to the CPU going to teardown  The driver needs to migrate the perf context if the current using CPU going to teardown. By the time calling the cpuhp::teardown() callback the cpu_online_mask() hasn't updated yet and still includes the CPU going to teardown. In current driver's implementation we may migrate the context to the teardown CPU and leads to the below calltrace:  ... [  368.104662][  T932] task:cpuhp/0         state:D stack:    0 pid:   15 ppid:     2 flags:0x00000008 [  368.113699][  T932] Call trace: [  368.116834][  T932]  __switch_to+0x7c/0xbc [  368.120924][  T932]  __schedule+0x338/0x6f0 [  368.125098][  T932]  schedule+0x50/0xe0 [  368.128926][  T932]  schedule_preempt_disabled+0x18/0x24 [  368.134229][  T932]  __mutex_lock.constprop.0+0x1d4/0x5dc [  368.139617][  T932]  __mutex_lock_slowpath+0x1c/0x30 [  368.144573][  T932]  mutex_lock+0x50/0x60 [  368.148579][  T932]  perf_pmu_migrate_context+0x84/0x2b0 [  368.153884][  T932]  hisi_pcie_pmu_offline_cpu+0x90/0xe0 [hisi_pcie_pmu] [  368.160579][  T932]  cpuhp_invoke_callback+0x2a0/0x650 [  368.165707][  T932]  cpuhp_thread_fun+0xe4/0x190 [  368.170316][  T932]  smpboot_thread_fn+0x15c/0x1a0 [  368.175099][  T932]  kthread+0x108/0x13c [  368.179012][  T932]  ret_from_fork+0x10/0x18 ...  Use function cpumask_any_but() to find one correct active cpu to fixes this issue.","modified":"2026-09-15T09:02:51.992961842Z","published":"2025-10-07T16:15:49.213Z","upstream":["CVE-2023-53656"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-53656"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.52-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53656.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.4-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53656.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.4-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53656.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}