A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploited to achieve local privilege escalation.
If perf_read_group() is called while an event's sibling_list is smaller than its child's sibling_list, it can increment or write to memory locations outside of the allocated buffer.
We recommend upgrading past commit 32671e3799ca2e4590773fd0e63aaa4229e50c06.
If perf_read_group() is called while an event's sibling_list is smaller than its child's sibling_list, it can increment or write to memory locations outside of the allocated buffer.
We recommend upgrading past commit 32671e3799ca2e4590773fd0e63aaa4229e50c06.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3710-1 | linux security update |
Debian DLA |
DLA-3711-1 | linux-5.10 security update |
Debian DSA |
DSA-5594-1 | linux security update |
EUVD |
EUVD-2023-58004 | A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploited to achieve local privilege escalation. If perf_read_group() is called while an event's sibling_list is smaller than its child's sibling_list, it can increment or write to memory locations outside of the allocated buffer. We recommend upgrading past commit 32671e3799ca2e4590773fd0e63aaa4229e50c06. |
Ubuntu USN |
USN-6494-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6494-2 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6497-1 | Linux kernel (OEM) vulnerabilities |
Ubuntu USN |
USN-6532-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6534-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6534-2 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6534-3 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6536-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6537-1 | Linux kernel (GCP) vulnerabilities |
Ubuntu USN |
USN-6548-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6548-2 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6548-3 | Linux kernel (Oracle) vulnerabilities |
Ubuntu USN |
USN-6549-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6549-2 | Linux kernel (GKE) vulnerabilities |
Ubuntu USN |
USN-6549-3 | Linux kernel (Low Latency) vulnerabilities |
Ubuntu USN |
USN-6548-4 | Linux kernel (GKE) vulnerabilities |
Ubuntu USN |
USN-6548-5 | Linux kernel (IoT) vulnerabilities |
Ubuntu USN |
USN-6549-4 | Linux kernel (Intel IoTG) vulnerabilities |
Ubuntu USN |
USN-6549-5 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6573-1 | Linux kernel (Azure) vulnerabilities |
Ubuntu USN |
USN-6635-1 | Linux kernel (GCP) vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 13 Feb 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploited to achieve local privilege escalation. If perf_read_group() is called while an event's sibling_list is smaller than its child's sibling_list, it can increment or write to memory locations outside of the allocated buffer. We recommend upgrading past commit 32671e3799ca2e4590773fd0e63aaa4229e50c06. | A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploited to achieve local privilege escalation. If perf_read_group() is called while an event's sibling_list is smaller than its child's sibling_list, it can increment or write to memory locations outside of the allocated buffer. We recommend upgrading past commit 32671e3799ca2e4590773fd0e63aaa4229e50c06. |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2025-02-13T17:25:43.494Z
Reserved: 2023-10-23T10:49:09.250Z
Link: CVE-2023-5717
No data.
Status : Modified
Published: 2023-10-25T18:17:43.913
Modified: 2025-02-13T18:15:59.940
Link: CVE-2023-5717
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Ubuntu USN