Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-31085
HistoryApr 24, 2023 - 12:00 a.m.

CVE-2023-31085

2023-04-2400:00:00
ubuntu.com
ubuntu.com
15
cve-2023-31085
linux kernel
divide-by-zero
bugzilla
user namespace

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

5.1%

An issue was discovered in drivers/mtd/ubi/cdev.c in the Linux kernel 6.2.
There is a divide-by-zero error in do_div(sz,mtd->erasesize), used
indirectly by ctrl_cdev_ioctl, when mtd->erasesize is 0.

Bugs

Notes

Author Note
Priority reason: Requires initial user namespace CAP_SYS_RESOURCE.
Rows per page:
1-10 of 931

References

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

5.1%