CVE-2023-2007
published 2023-04-24CVE-2023-2007: The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An…
PriorityP344high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.29%
20.7th percentile
The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 6.0.2-1 (bookworm) | linux 6.0.2-1 (bookworm) |
| linux | linux_kernel | < 6.0 | 6.0 |
| linux | linux_kernel | >= 0 < 5.10.191-1 | 5.10.191-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| msrc | cbl2_kernel_5.15.126.1-1_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: DPT I2O controller TOCTOU information disclosure vulnerability
vendor_redhat·2023-04-13·CVSS 7.8
CVE-2023-2007 [HIGH] CWE-667 kernel: DPT I2O controller TOCTOU information disclosure vulnerability
kernel: DPT I2O controller TOCTOU information disclosure vulnerability
The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel.
A time-of-check time-of-use (TOCTOU) information disclosure vulnerability was found in the Linux Kernel DPT I2O controller. This issue results from the lack of proper locking when performing operations on an object, allowing a privileged local user to escalate privileges and execute arbitrary code in the context of the kernel.
Statement: No Red Hat products are affected by this flaw, as the i2o driver is not included
Microsoft
The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction w
vendor_msrc·2023-04-11·CVSS 7.8
CVE-2023-2007 [HIGH] CWE-667 The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction w
The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. Se
Debian
CVE-2023-2007: linux - The specific flaw exists within the DPT I2O Controller driver. The issue results...
vendor_debian·2023·CVSS 7.8
CVE-2023-2007 [HIGH] CVE-2023-2007: linux - The specific flaw exists within the DPT I2O Controller driver. The issue results...
The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel.
Scope: local
bookworm: resolved (fixed in 6.0.2-1)
bullseye: resolved (fixed in 5.10.191-1)
forky: resolved (fixed in 6.0.2-1)
sid: resolved (fixed in 6.0.2-1)
trixie: resolved (fixed in 6.0.2-1)
GHSA
GHSA-q945-mj3h-45f2: The specific flaw exists within the DPT I2O Controller driver
ghsa_unreviewed·2023-04-25
CVE-2023-2007 [HIGH] CWE-367 GHSA-q945-mj3h-45f2: The specific flaw exists within the DPT I2O Controller driver
The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel.
OSV
CVE-2023-2007: The specific flaw exists within the DPT I2O Controller driver
osv·2023-04-24·CVSS 7.8
CVE-2023-2007 [HIGH] CVE-2023-2007: The specific flaw exists within the DPT I2O Controller driver
The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel.
Suricata
ET WEB_SPECIFIC_APPS Joomla! SQL Injection Attempt -- categories.php text SELECT
suricata·2010-07-30
CVE-2007-0373 ET WEB_SPECIFIC_APPS Joomla! SQL Injection Attempt -- categories.php text SELECT
ET WEB_SPECIFIC_APPS Joomla! SQL Injection Attempt -- categories.php text SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Joomla! SQL Injection Attempt -- categories.php text SELECT"; flow:established,to_server; http.uri; content:"/plugins/search/categories.php?"; nocase; content:"text="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; distance:0; reference:cve,2007-0373; reference:url,www.securityfocus.com/bid/22122; classtype:web-application-attack; sid:2005438; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, cve CVE_2007_0373, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2023_06_05, mitre_tactic_id TA0001, mitre_tactic_name
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/torvalds/linux/commit/b04e75a4a8a81887386a0d2dbf605a48e779d2a0https://lists.debian.org/debian-lts-announce/2023/07/msg00030.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00027.htmlhttps://security.netapp.com/advisory/ntap-20240119-0011/https://www.debian.org/security/2023/dsa-5480https://github.com/torvalds/linux/commit/b04e75a4a8a81887386a0d2dbf605a48e779d2a0https://lists.debian.org/debian-lts-announce/2023/07/msg00030.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00027.htmlhttps://security.netapp.com/advisory/ntap-20240119-0011/https://www.debian.org/security/2023/dsa-5480
2023-04-24
Published