CVE-2023-5717

CWE-787Out-of-bounds Write26 documents8 sources
Severity
7.8HIGH
EPSS
0.2%
top 54.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 25
Latest updateFeb 14

Description

A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploited to achieve local privilege escalation. If perf_read_group() is called while an event's sibling_list is smaller than its child's sibling_list, it can increment or write to memory locations outside of the allocated buffer. We recommend upgrading past commit 32671e3799ca2e4590773fd0e63aaa4229e50c06.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5linux/kernel4.46.6
NVDlinux/linux_kernel3.2.953.3+9
Debianlinux< 5.10.205-2+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-gv6g-gf42-rjg7: A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploited to achieve local priv2023-10-25
CVEList
Out-of-bounds write in Linux kernel's Linux Kernel Performance Events (perf) component2023-10-25
OSV
CVE-2023-5717: A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploited to achieve local priv2023-10-25

📋Vendor Advisories

22
Ubuntu
Linux kernel (GCP) vulnerabilities2024-02-14
Ubuntu
Linux kernel vulnerabilities2024-01-10
Ubuntu
Linux kernel (IoT) vulnerabilities2024-01-10
Ubuntu
Linux kernel (Azure) vulnerabilities2024-01-09
Ubuntu
Linux kernel (GKE) vulnerabilities2024-01-09