PT-2023-2675 · Linux+8 · Linux Kernel+8
Alexandra Sandulescu
+1
·
Published
2023-01-21
·
Updated
2024-04-15
·
CVE-2023-0458
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Linux Kernel versions prior to 6.1.8
Description
A speculative pointer dereference problem exists in the Linux Kernel on the
do prlimit() function. The resource argument value is controlled and is used in pointer arithmetic for the rlim variable and can be used to leak the contents.Recommendations
Upgrade past version 6.1.8 or apply commit 739790605705ddcf18f21782b9c99ad7d53a8c11 to resolve the issue. As a temporary workaround, consider restricting access to the
do prlimit() function until a patch is available.Fix
Information Disclosure
NULL Pointer Dereference
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Linux Kernel
Linuxmint
Red Hat
Rocky Linux
Ubuntu