CVE-2023-23005
published 2023-03-01CVE-2023-23005: In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case, whereas it is…
PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
18.8th percentile
In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case, whereas it is actually an error pointer). NOTE: this is disputed by third parties because there are no realistic cases in which a user can cause the alloc_memory_type error case to be reached.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.3.7-1 (forky) | linux 6.3.7-1 (forky) |
| linux | linux_kernel | < 6.2 | 6.2 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| msrc | cbl2_kernel_5.15.111.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_kernel_5.10.174.1-1_on_cbl_mariner_1.0 | — | — |
| suse | linux_enterprise_server | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ghmc-655x-wwhc: In the Linux kernel before 6
ghsa_unreviewed·2023-03-01
CVE-2023-23005 [MEDIUM] CWE-476 GHSA-ghmc-655x-wwhc: In the Linux kernel before 6
In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case, whereas it is actually an error pointer).
OSV
CVE-2023-23005: In the Linux kernel before 6
osv·2023-03-01·CVSS 5.5
CVE-2023-23005 [MEDIUM] CVE-2023-23005: In the Linux kernel before 6
In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case, whereas it is actually an error pointer). NOTE: this is disputed by third parties because there are no realistic cases in which a user can cause the alloc_memory_type error case to be reached.
Microsoft
In the Linux kernel before 6.2 mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case whereas it is actually an error pointer). NOTE: this is dispu
vendor_msrc·2023-03-14·CVSS 5.5
CVE-2023-23005 [MEDIUM] CWE-476 In the Linux kernel before 6.2 mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case whereas it is actually an error pointer). NOTE: this is dispu
In the Linux kernel before 6.2 mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case whereas it is actually an error pointer). NOTE: this is disputed by third parties because there are no realistic cases in which a user can cause the alloc_memory_type error case to be reached.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CS
Debian
CVE-2023-23005: linux - In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory...
vendor_debian·2023·CVSS 5.5
CVE-2023-23005 [MEDIUM] CVE-2023-23005: linux - In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory...
In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case, whereas it is actually an error pointer). NOTE: this is disputed by third parties because there are no realistic cases in which a user can cause the alloc_memory_type error case to be reached.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 6.3.7-1)
sid: resolved (fixed in 6.3.7-1)
trixie: resolved (fixed in 6.3.7-1)
Red Hat
kernel: incorrect check for error case in the memory_tier_init
vendor_redhat·2022-12-01·CVSS 5.5
CVE-2023-23005 [MEDIUM] CWE-252 kernel: incorrect check for error case in the memory_tier_init
kernel: incorrect check for error case in the memory_tier_init
In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case, whereas it is actually an error pointer). NOTE: this is disputed by third parties because there are no realistic cases in which a user can cause the alloc_memory_type error case to be reached.
A flaw was found in the Linux kernel’s mm/memory-tiers.c functionality in the memory_tier_init function, where an incorrect return value check from the alloc_memory_type occurs. The CVE is disputed because there are no realistic cases in which a user can cause the alloc_memory_type error case to be reached.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enter
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.suse.com/show_bug.cgi?id=1208844#c2https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2https://github.com/torvalds/linux/commit/4a625ceee8a0ab0273534cb6b432ce6b331db5eehttps://bugzilla.suse.com/show_bug.cgi?id=1208844#c2https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2https://github.com/torvalds/linux/commit/4a625ceee8a0ab0273534cb6b432ce6b331db5ee
2023-03-01
Published