Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-20937
HistoryFeb 28, 2023 - 12:00 a.m.

CVE-2023-20937

2023-02-2800:00:00
ubuntu.com
ubuntu.com
18
android
linux kernel
memory corruption
escalation of privilege
config_speculative_page_fault
exploit

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.1%

In several functions of the Android Linux kernel, there is a possible way
to corrupt memory due to a use after free. This could lead to local
escalation of privilege with no additional execution privileges needed.
User interaction is not needed for exploitation.Product: AndroidVersions:
Android kernelAndroid ID: A-257443051References: Upstream kernel

Notes

Author Note
sbeattie this is likely Android specific, as it’s an issue with the interaction of CONFIG_SPECULATIVE_PAGE_FAULT, which never made it upstream (see lore link for thread).

References

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.1%