cbcvebase.
CVE-2023-0458
published 2023-04-26

CVE-2023-0458: A speculative pointer dereference problem exists in the Linux Kernel on the do_prlimit() function. The resource argument value is controlled and is used in…

PriorityP420medium4.7CVSS 3.1
AVLACHPRLUINSUCHINAN
EPSS
0.72%
50.4th percentile
A speculative pointer dereference problem exists in the Linux Kernel on the do_prlimit() function. The resource argument value is controlled and is used in pointer arithmetic for the 'rlim' variable and can be used to leak the contents. We recommend upgrading past version 6.1.8 or commit 739790605705ddcf18f21782b9c99ad7d53a8c11

Affected

17 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.8-1 (bookworm)linux 6.1.8-1 (bookworm)
linuxlinux_kernel< 6.1.86.1.8
linuxlinux_kernel<= 6.1.8
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.8-16.1.8-1
linuxlinux_kernel>= 0 < 6.1.8-16.1.8-1
linuxlinux_kernel>= 0 < 6.1.8-16.1.8-1
linuxlinux_kernel>= 0 < 3.13.0-193.2443.13.0-193.244
linuxlinux_kernel>= 0 < 4.4.0-243.2774.4.0-243.277
msrccbl2_kernel_5.15.111.1-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_kernel_5.10.179.1-1_on_cbl_mariner_1.0

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_msrc4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.