Description
A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploited to achieve local privilege escalation.
If perf_read_group() is called while an event's sibling_list is smaller than its child's sibling_list, it can increment or write to memory locations outside of the allocated buffer.
We recommend upgrading past commit 32671e3799ca2e4590773fd0e63aaa4229e50c06.
If perf_read_group() is called while an event's sibling_list is smaller than its child's sibling_list, it can increment or write to memory locations outside of the allocated buffer.
We recommend upgrading past commit 32671e3799ca2e4590773fd0e63aaa4229e50c06.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3710-1 | linux security update |
Debian DLA |
DLA-3711-1 | linux-5.10 security update |
Debian DSA |
DSA-5594-1 | linux security update |
EUVD |
EUVD-2023-58004 | A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploited to achieve local privilege escalation. If perf_read_group() is called while an event's sibling_list is smaller than its child's sibling_list, it can increment or write to memory locations outside of the allocated buffer. We recommend upgrading past commit 32671e3799ca2e4590773fd0e63aaa4229e50c06. |
Ubuntu USN |
USN-6494-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6494-2 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6497-1 | Linux kernel (OEM) vulnerabilities |
Ubuntu USN |
USN-6532-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6534-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6534-2 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6534-3 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6536-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6537-1 | Linux kernel (GCP) vulnerabilities |
Ubuntu USN |
USN-6548-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6548-2 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6548-3 | Linux kernel (Oracle) vulnerabilities |
Ubuntu USN |
USN-6549-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6549-2 | Linux kernel (GKE) vulnerabilities |
Ubuntu USN |
USN-6549-3 | Linux kernel (Low Latency) vulnerabilities |
Ubuntu USN |
USN-6548-4 | Linux kernel (GKE) vulnerabilities |
Ubuntu USN |
USN-6548-5 | Linux kernel (IoT) vulnerabilities |
Ubuntu USN |
USN-6549-4 | Linux kernel (Intel IoTG) vulnerabilities |
Ubuntu USN |
USN-6549-5 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6573-1 | Linux kernel (Azure) vulnerabilities |
Ubuntu USN |
USN-6635-1 | Linux kernel (GCP) vulnerabilities |
References
History
Thu, 26 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Feb 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploited to achieve local privilege escalation. If perf_read_group() is called while an event's sibling_list is smaller than its child's sibling_list, it can increment or write to memory locations outside of the allocated buffer. We recommend upgrading past commit 32671e3799ca2e4590773fd0e63aaa4229e50c06. | A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploited to achieve local privilege escalation. If perf_read_group() is called while an event's sibling_list is smaller than its child's sibling_list, it can increment or write to memory locations outside of the allocated buffer. We recommend upgrading past commit 32671e3799ca2e4590773fd0e63aaa4229e50c06. |
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2026-02-25T17:20:08.857Z
Reserved: 2023-10-23T10:49:09.250Z
Link: CVE-2023-5717
Updated: 2024-08-02T08:07:32.716Z
Status : Modified
Published: 2023-10-25T18:17:43.913
Modified: 2025-02-13T18:15:59.940
Link: CVE-2023-5717
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Ubuntu USN