cbcvebase.
CVE-2023-6931
published 2023-12-19

CVE-2023-6931: A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A…

high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group(). We recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.

Affected

16 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.69-1 (bookworm)linux 6.1.69-1 (bookworm)
googlechrome_chrome
linuxkernel>= 4.3 < 6.76.7
linuxlinux_kernel>= 0 < 5.10.205-25.10.205-2
linuxlinux_kernel>= 0 < 6.1.69-16.1.69-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 5.4.0-170.1885.4.0-170.188
linuxlinux_kernel>= 0 < 5.15.0-92.1025.15.0-92.102
linuxlinux_kernel>= 0 < 4.4.0-250.2844.4.0-250.284
linuxlinux_kernel>= 0 < 4.15.0-221.2324.15.0-221.232
linuxlinux_kernel>= 4.3 < 6.76.7
msrcazl3_kernel_6.6.35.1-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.92.2-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.143.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH