Lucene search

K
cvelistGoogleCVELIST:CVE-2023-2163
HistorySep 20, 2023 - 5:02 a.m.

CVE-2023-2163 Incorrect Verifier Branch Pruning Logic Leads To Arbitrary Read/Write In Linux Kernel and Lateral Privilege Escalation

2023-09-2005:02:38
CWE-682
Google
www.cve.org
1
cve-2023-2163
verifier pruning
linux kernel
arbitrary read/write
lateral privilege escalation
container escape

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

9.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe
code paths being incorrectly marked as safe, resulting in arbitrary read/write in
kernel memory, lateral privilege escalation, and container escape.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Linux Kernel",
    "vendor": "Linux",
    "versions": [
      {
        "lessThan": "5.4",
        "status": "unaffected",
        "version": "0",
        "versionType": "custom"
      },
      {
        "lessThan": "71b547f561247897a0a14f3082730156c0533fed",
        "status": "affected",
        "version": "0",
        "versionType": "git"
      }
    ]
  }
]

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

9.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%