cbcvebase.
CVE-2023-1513
published 2023-03-23

CVE-2023-1513: A flaw was found in KVM. When calling the KVM_GET_DEBUGREGS ioctl, on 32-bit systems, there might be some uninitialized portions of the kvm_debugregs structure…

low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
A flaw was found in KVM. When calling the KVM_GET_DEBUGREGS ioctl, on 32-bit systems, there might be some uninitialized portions of the kvm_debugregs structure that could be copied to userspace, causing an information leak.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.15-1 (bookworm)linux 6.1.15-1 (bookworm)
fedoraprojectfedora
linuxlinux_kernel< 6.26.2
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.15-16.1.15-1
linuxlinux_kernel>= 0 < 6.1.15-16.1.15-1
linuxlinux_kernel>= 0 < 6.1.15-16.1.15-1
linuxlinux_kernel>= 0 < 4.15.0-211.2224.15.0-211.222
linuxlinux_kernel>= 0 < 5.4.0-149.1665.4.0-149.166
linuxlinux_kernel>= 0 < 5.15.0-72.795.15.0-72.79
msrccbl2_kernel_5.15.102.1-3_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_kernel_5.10.174.1-1_on_cbl_mariner_1.0
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv5.5MEDIUM