CVE-2023-40791Kernel vulnerability

8 documents8 sources
Severity
6.3MEDIUMNVD
EPSS
0.0%
top 87.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 16
Latest updateOct 17

Description

extract_user_to_sg in lib/scatterlist.c in the Linux kernel before 6.4.12 fails to unpin pages in a certain situation, as demonstrated by a WARNING for try_grab_page.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:HExploitability: 1.0 | Impact: 5.2

Affected Packages2 packages

NVDlinux/linux_kernel< 6.4.12
Debianlinux/linux_kernel< 6.4.13-1+1

Patches

🔴Vulnerability Details

3
CVEList
CVE-2023-40791: extract_user_to_sg in lib/scatterlist2023-10-16
GHSA
GHSA-fmxm-fv27-gg49: extract_user_to_sg in lib/scatterlist2023-10-16
OSV
CVE-2023-40791: extract_user_to_sg in lib/scatterlist2023-10-16

📋Vendor Advisories

3
Microsoft
extract_user_to_sg in lib/scatterlist.c in the Linux kernel before 6.4.12 fails to unpin pages in a certain situation as demonstrated by a WARNING for try_grab_page.2023-10-10
Red Hat
kernel: lib/scatterlist.c fails to unpin pages2023-08-03
Debian
CVE-2023-40791: linux - extract_user_to_sg in lib/scatterlist.c in the Linux kernel before 6.4.12 fails ...2023

💬Community

1
Bugzilla
CVE-2023-40791 kernel: lib/scatterlist.c fails to unpin pages2023-10-17