CVE-2023-5717
published 2023-10-25CVE-2023-5717: A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploited to achieve local privilege…
high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploited to achieve local privilege escalation.
If perf_read_group() is called while an event's sibling_list is smaller than its child's sibling_list, it can increment or write to memory locations outside of the allocated buffer.
We recommend upgrading past commit 32671e3799ca2e4590773fd0e63aaa4229e50c06.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.64-1 (bookworm) | linux 6.1.64-1 (bookworm) |
| linux | kernel | >= 4.4 < 6.6 | 6.6 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.205-2 | 5.10.205-2 |
| linux | linux_kernel | >= 0 < 6.1.64-1 | 6.1.64-1 |
| linux | linux_kernel | >= 0 < 6.5.10-1 | 6.5.10-1 |
| linux | linux_kernel | >= 0 < 6.5.10-1 | 6.5.10-1 |
| linux | linux_kernel | >= 0 < 5.4.0-169.187 | 5.4.0-169.187 |
| linux | linux_kernel | >= 0 < 5.15.0-91.101 | 5.15.0-91.101 |
| linux | linux_kernel | >= 0 < 4.4.0-248.282 | 4.4.0-248.282 |
| linux | linux_kernel | >= 0 < 4.15.0-220.231 | 4.15.0-220.231 |
| linux | linux_kernel | >= 3.16.50 < 3.17 | 3.17 |
| linux | linux_kernel | >= 3.2.95 < 3.3 | 3.3 |
| linux | linux_kernel | >= 4.15 < 4.19.297 | 4.19.297 |
| linux | linux_kernel | >= 4.20 < 5.4.259 | 5.4.259 |
| linux | linux_kernel | >= 4.4 < 4.14.328 | 4.14.328 |
| linux | linux_kernel | >= 5.11 < 5.15.137 | 5.15.137 |
| linux | linux_kernel | >= 5.16 < 6.1.60 | 6.1.60 |
| linux | linux_kernel | >= 5.5 < 5.10.199 | 5.10.199 |
| linux | linux_kernel | >= 6.2 < 6.5.9 | 6.5.9 |
| msrc | cbl2_hyperv-daemons_5.15.137.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_kernel_5.15.137.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| ubuntu | linux-gcp | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH