Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-2513
HistoryMay 08, 2023 - 12:00 a.m.

CVE-2023-2513

2023-05-0800:00:00
ubuntu.com
ubuntu.com
18
linux
ext4
filesystem
vulnerability
use-after-free
cve-2023-2513
privileged user
system crash
undefined behaviors

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%

A use-after-free vulnerability was found in the Linux kernel’s ext4
filesystem in the way it handled the extra inode size for extended
attributes. This flaw could allow a privileged local user to cause a system
crash or other undefined behaviors.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchlinux< 4.15.0-197.208UNKNOWN
ubuntu20.04noarchlinux< 5.4.0-132.148UNKNOWN
ubuntu22.04noarchlinux< 5.15.0-53.59UNKNOWN
ubuntu16.04noarchlinux< 4.4.0-243.277UNKNOWN
ubuntu18.04noarchlinux-aws< 4.15.0-1143.155UNKNOWN
ubuntu20.04noarchlinux-aws< 5.4.0-1089.97UNKNOWN
ubuntu22.04noarchlinux-aws< 5.15.0-1023.27UNKNOWN
ubuntu14.04noarchlinux-aws< 4.4.0-1121.127UNKNOWN
ubuntu16.04noarchlinux-aws< 4.4.0-1159.174UNKNOWN
ubuntu20.04noarchlinux-aws-5.15< 5.15.0-1023.27~20.04.1UNKNOWN
Rows per page:
1-10 of 631

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%