Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-0459
HistoryApr 20, 2023 - 12:00 a.m.

CVE-2023-0459

2023-04-2000:00:00
ubuntu.com
ubuntu.com
24
linux
kernel
vulnerability
access_ok check
user access

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

0.0004 Low

EPSS

Percentile

9.2%

Copy_from_user on 64-bit versions of the Linux kernel does not implement
the __uaccess_begin_nospec allowing a user to bypass the “access_ok” check
and pass a kernel pointer to copy_from_user(). This would allow an attacker
to leak information. We recommend upgrading beyond commit
74e19ef0ff8061ef55957c3abd71614ef0f42f47

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchlinux< 4.15.0-211.222UNKNOWN
ubuntu20.04noarchlinux< 5.4.0-149.166UNKNOWN
ubuntu22.04noarchlinux< 5.15.0-72.79UNKNOWN
ubuntu22.10noarchlinux< 5.19.0-42.43UNKNOWN
ubuntu18.04noarchlinux-aws< 4.15.0-1156.169UNKNOWN
ubuntu20.04noarchlinux-aws< 5.4.0-1102.110UNKNOWN
ubuntu22.04noarchlinux-aws< 5.15.0-1036.40UNKNOWN
ubuntu22.10noarchlinux-aws< 5.19.0-1025.26UNKNOWN
ubuntu20.04noarchlinux-aws-5.15< 5.15.0-1036.40~20.04.1UNKNOWN
ubuntu18.04noarchlinux-aws-5.4< 5.4.0-1103.111~18.04.1UNKNOWN
Rows per page:
1-10 of 741

References

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

0.0004 Low

EPSS

Percentile

9.2%