PT-2023-7578 · Linux+4 · Linux Kernel+4

Oded Gabbay

+1

·

Published

2023-11-22

·

Updated

2025-10-03

·

CVE-2023-50431

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 6.6.5
Description The issue is related to the sec attest info function in the Linux kernel, which allows an information leak to user space because info->pad0 is not initialized. This can potentially allow an attacker to gain unauthorized access to protected information.
Recommendations For Linux kernel versions through 6.6.5, consider updating to a version that includes the necessary fix for the sec attest info function to prevent information leaks. As a temporary workaround, consider restricting access to the sec attest info function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-8254
ALT-PU-2024-14046
ALT-PU-2024-6818
ALT-PU-2025-12647
AZL-32175
AZL-62064
BDU:2023-08634
CVE-2023-50431
USN-6688-1
USN-6724-1
USN-6724-2

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Ubuntu