CVE-2023-6931

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
19/12/2023
Last modified:
13/02/2025

Description

A heap out-of-bounds write vulnerability in the Linux kernel&amp;#39;s Performance Events system component can be exploited to achieve local privilege escalation.<br /> <br /> A perf_event&amp;#39;s read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group().<br /> <br /> We recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.3 (including) 6.7 (excluding)
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*