PT-2023-7578 · Linux+4 · Linux Kernel+4

Oded Gabbay

+1

·

Publicado

2023-11-22

·

Atualizado

2025-10-03

·

CVE-2023-50431

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 6.6.5
Description The issue is related to the sec attest info function in the Linux kernel, which allows an information leak to user space because info->pad0 is not initialized. This can potentially allow an attacker to gain unauthorized access to protected information.
Recommendations For Linux kernel versions through 6.6.5, consider updating to a version that includes the necessary fix for the sec attest info function to prevent information leaks. As a temporary workaround, consider restricting access to the sec attest info function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-8254
ALT-PU-2024-14046
ALT-PU-2024-6818
ALT-PU-2025-12647
AZL-32175
AZL-62064
BDU:2023-08634
CVE-2023-50431
USN-6688-1
USN-6724-1
USN-6724-2

Produtos afetados

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Ubuntu