Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-2163

Опубликовано: 20 сент. 2023
Источник: debian
EPSS Низкий

Описание

Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe code paths being incorrectly marked as safe, resulting in arbitrary read/write in kernel memory, lateral privilege escalation, and container escape.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed6.1.27-1package
linuxfixed5.10.179-1bullseyepackage
linuxnot-affectedbusterpackage

Примечания

  • https://git.kernel.org/linus/71b547f561247897a0a14f3082730156c0533fed (6.3)

  • https://bughunters.google.com/blog/6303226026131456/a-deep-dive-into-cve-2023-2163-how-we-found-and-fixed-an-ebpf-linux-kernel-vulnerability

EPSS

Процентиль: 39%
0.00172
Низкий

Связанные уязвимости

CVSS3: 10
ubuntu
около 2 лет назад

Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe code paths being incorrectly marked as safe, resulting in arbitrary read/write in kernel memory, lateral privilege escalation, and container escape.

CVSS3: 8.2
redhat
больше 2 лет назад

Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe code paths being incorrectly marked as safe, resulting in arbitrary read/write in kernel memory, lateral privilege escalation, and container escape.

CVSS3: 10
nvd
около 2 лет назад

Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe code paths being incorrectly marked as safe, resulting in arbitrary read/write in kernel memory, lateral privilege escalation, and container escape.

CVSS3: 8.8
msrc
около 2 лет назад

Incorrect Verifier Branch Pruning Logic Leads To Arbitrary Read/Write In Linux Kernel and Lateral Privilege Escalation

suse-cvrf
почти 2 года назад

Security update for the Linux Kernel (Live Patch 41 for SLE 15 SP2)

EPSS

Процентиль: 39%
0.00172
Низкий