CVE-2023-2124Out-of-bounds Write in Kernel

Severity
7.8HIGHNVD
OSV6.5OSV5.5OSV4.7
EPSS
0.0%
top 94.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 15
Latest updateJun 13

Description

An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image after failure (with a dirty log journal). This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages8 packages

debiandebian/linux< linux 6.1.37-1 (bookworm)
Debianlinux/linux_kernel< 5.10.191-1+3
Ubuntulinux/linux_kernel< 5.4.0-156.173+3
CVEListV5linux/linux_kernelLinux kernel 6.4-rc1

Also affects: Debian Linux 11.0, 12.0

Patches

🔴Vulnerability Details

16
OSV
linux-azure-fde-5.15 vulnerabilities2023-09-06
OSV
linux-azure-5.4 vulnerabilities2023-09-04
OSV
linux-azure vulnerabilities2023-08-31
OSV
linux-azure, linux-azure-5.15, linux-azure-fde vulnerabilities2023-08-31
OSV
linux-bluefield, linux-ibm vulnerabilities2023-08-29

📋Vendor Advisories

21
CISA ICS
Siemens TIM 1531 IRC2024-06-13
CISA ICS
Siemens SCALANCE XCM-/XRM-3002024-02-15
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS2024-02-14
Ubuntu
Linux kernel (Azure CVM) vulnerabilities2023-09-06
Ubuntu
Linux kernel (Azure) vulnerabilities2023-09-04

💬Community

1
Bugzilla
CVE-2023-2124 kernel: OOB access in the Linux kernel's XFS subsystem2023-04-17