Lucene search

K
nvd[email protected]NVD:CVE-2023-2194
HistoryApr 20, 2023 - 9:15 p.m.

CVE-2023-2194

2023-04-2021:15:09
CWE-787
web.nvd.nist.gov
out-of-bounds write
vulnerability
linux kernel
slimpro i2c
local privileged user
crash
code execution

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

An out-of-bounds write vulnerability was found in the Linux kernel’s SLIMpro I2C device driver. The userspace “data->block[0]” variable was not capped to a number between 0-255 and was used as the size of a memcpy, possibly writing beyond the end of dma_buffer. This flaw could allow a local privileged user to crash the system or potentially achieve code execution.

Affected configurations

NVD
Node
linuxlinux_kernelRange<6.3
OR
linuxlinux_kernelMatch6.3rc1
OR
linuxlinux_kernelMatch6.3rc2
OR
linuxlinux_kernelMatch6.3rc3
Node
fedoraprojectfedoraMatch38
Node
redhatenterprise_linuxMatch8.0
OR
redhatenterprise_linuxMatch9.0

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%