Lucene search

K
nvd[email protected]NVD:CVE-2023-2163
HistorySep 20, 2023 - 6:15 a.m.

CVE-2023-2163

2023-09-2006:15:10
CWE-682
web.nvd.nist.gov
1
linux kernel
cve-2023-2163
verifier pruning
vulnerability
arbitrary read/write
memory
privilege escalation
container escape

8.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

9.7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe
code paths being incorrectly marked as safe, resulting in arbitrary read/write in
kernel memory, lateral privilege escalation, and container escape.

Affected configurations

NVD
Node
linuxlinux_kernelRange5.35.4.242
OR
linuxlinux_kernelRange5.55.10.179
OR
linuxlinux_kernelRange5.115.15.109
OR
linuxlinux_kernelRange5.166.1.26
OR
linuxlinux_kernelRange6.26.2.13

8.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

9.7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%