Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-0160
HistoryJul 18, 2023 - 12:00 a.m.

CVE-2023-0160

2023-07-1800:00:00
ubuntu.com
ubuntu.com
32
linux kernel
bpf subsystem
deadlock flaw
local user
system crash

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0

Percentile

5.1%

A deadlock flaw was found in the Linux kernel’s BPF subsystem. This flaw
allows a local user to potentially crash the system.

Bugs

Notes

Author Note
sbeattie first attempt to fix was reverted in 8c5c2a4898e3 (“bpf, sockmap: Revert buggy deadlock fix in the sockhash and sockmap”) unfixed upstream as of 2023.06.14

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0

Percentile

5.1%