PT-2023-2590 · Linux+10 · Linux Kernel+10

Budimir Markovic

·

Published

2023-03-15

·

Updated

2024-04-15

·

CVE-2023-2235

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux Kernel (affected versions not specified)
Description A use-after-free vulnerability in the Linux Kernel Performance Events system can be exploited to achieve local privilege escalation. The perf group detach function did not check the event's siblings' attach state before calling add event to groups(), but remove on exec made it possible to call list del event() on before detaching from their group, making it possible to use a dangling pointer causing a use-after-free vulnerability.
Recommendations Upgrade past commit fd0815f632c24878e325821943edccc7fde947a2 to resolve the issue. As a temporary workaround, consider restricting access to the perf group detach function until a patch is available.

Fix

LPE

Use After Free

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:3708
ALSA-2023:3723
ALSA-2023:4517
ALSA-2023:4541
ALT-PU-2023-1878
ALT-PU-2023-1881
ALT-PU-2023-2050
ALT-PU-2023-4663
ALT-PU-2024-4263
ALT-PU-2024-4843
AZL-26389
BDU:2023-02407
CESA-2023_4517
CESA-2023_4541
CVE-2023-2235
OPENSUSE-SU-2023_2646-1
OPENSUSE-SU-2023_2871-1
OPENSUSE-SU-2023_3055-1
OPENSUSE-SU-2023_3063-1
OPENSUSE-SU-2023_3079-1
OPENSUSE-SU-2023_3116-1
OPENSUSE-SU-2023_3153-1
RHSA-2023:3705
RHSA-2023:3708
RHSA-2023:3723
RHSA-2023:4137
RHSA-2023:4138
RHSA-2023:4517
RHSA-2023:4541
RHSA-2023:5627
RHSA-2023_3708
RHSA-2023_3723
RHSA-2023_4517
RHSA-2023_4541
RLSA-2023:4517
RLSA-2023:4541
SUSE-SU-2023:2140-1
SUSE-SU-2023:2141-1
SUSE-SU-2023:2231-1
SUSE-SU-2023:2646-1
SUSE-SU-2023:2809-1
SUSE-SU-2023:2871-1
SUSE-SU-2023:3055-1
SUSE-SU-2023:3063-1
SUSE-SU-2023:3079-1
SUSE-SU-2023:3116-1
SUSE-SU-2023:3153-1
USN-6175-1
USN-6186-1
USN-6300-1
USN-6311-1
USN-6332-1
USN-6347-1
USN-6385-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linux Kernel
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu