Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2023-2163
HistorySep 20, 2023 - 6:15 a.m.

CVE-2023-2163

2023-09-2006:15:10
Debian Security Bug Tracker
security-tracker.debian.org
61
linux kernel
bpf
cve-2023-2163
unsafe code paths
arbitrary read/write
kernel memory
privilege escalation
container escape
unix

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

8.4 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe code paths being incorrectly marked as safe, resulting in arbitrary read/write in kernel memory, lateral privilege escalation, and container escape.

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

8.4 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%