PT-2023-5552 · Linux+5 · Linux Kernel+5

Ga_Ryo

+1

·

Published

2023-01-20

·

Updated

2026-03-13

·

CVE-2023-39191

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux Kernel (affected versions not specified)
Description The issue is related to an improper input validation flaw in the eBPF subsystem of the Linux kernel. This flaw occurs due to a lack of proper validation of dynamic pointers within user-supplied eBPF programs prior to executing them. As a result, an attacker with CAP BPF privileges may be able to escalate privileges and execute arbitrary code in the context of the kernel.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-14046
ALT-PU-2024-6818
AZL-31150
BDU:2023-06203
CVE-2023-39191
ECHO-FFFA-184D-8E08
OPENSUSE-SU-2023_4343-1
OPENSUSE-SU-2023_4375-1
OPENSUSE-SU-2023_4414-1
RHSA-2023:6583
RHSA-2023_6583
RHSA-2024:0381
RHSA-2024:0439
RHSA-2024:0448
SUSE-SU-2023:4343-1
SUSE-SU-2023:4375-1
SUSE-SU-2023:4414-1
SUSE-SU-2024:0986-1
SUSE-SU-2024:0995-1
SUSE-SU-2024:1023-1
SUSE-SU-2024:1039-1
SUSE-SU-2024:1045-1
SUSE-SU-2024:1097-1
ZDI-23-1489

Affected Products

Alt Linux
Debian
Linux Kernel
Red Hat
Red Os
Suse