PT-2023-2675 · Linux+8 · Linux Kernel+8

Alexandra Sandulescu

+1

·

Published

2023-01-21

·

Updated

2024-04-15

·

CVE-2023-0458

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux Kernel versions prior to 6.1.8
Description A speculative pointer dereference problem exists in the Linux Kernel on the do prlimit() function. The resource argument value is controlled and is used in pointer arithmetic for the rlim variable and can be used to leak the contents.
Recommendations Upgrade past version 6.1.8 or apply commit 739790605705ddcf18f21782b9c99ad7d53a8c11 to resolve the issue. As a temporary workaround, consider restricting access to the do prlimit() function until a patch is available.

Fix

Information Disclosure

NULL Pointer Dereference

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2023:4377
ALSA-2023:4378
ALSA-2023:7077
ALT-PU-2023-1124
ALT-PU-2023-1126
ALT-PU-2023-1684
ALT-PU-2023-1741
ALT-PU-2023-1814
ALT-PU-2023-1944
ALT-PU-2023-4894
ALT-PU-2024-4263
ALT-PU-2024-4843
AZL-26415
BDU:2023-02515
CESA-2023_6901
CESA-2023_7077
CVE-2023-0458
DLA-3403-1
DLA-3404-1
OESA-2023-1274
OESA-2023-1275
OESA-2023-1284
RHSA-2023:4377
RHSA-2023:4378
RHSA-2023:4801
RHSA-2023:4814
RHSA-2023:6901
RHSA-2023:7077
RHSA-2023_4377
RHSA-2023_4378
RHSA-2023_6901
RHSA-2023_7077
RHSA-2024:0575
RHSA-2024:0724
RLSA-2023:4378
USN-6079-1
USN-6091-1
USN-6093-1
USN-6096-1
USN-6134-1
USN-6222-1
USN-6254-1
USN-6256-1
USN-6341-1
USN-6385-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linux Kernel
Linuxmint
Red Hat
Rocky Linux
Ubuntu