A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation.

A perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group().

We recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3710-1 linux security update
Debian DLA Debian DLA DLA-3711-1 linux-5.10 security update
Debian DSA Debian DSA DSA-5593-1 linux security update
Debian DSA Debian DSA DSA-5594-1 linux security update
EUVD EUVD EUVD-2023-59129 A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group(). We recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.
Ubuntu USN Ubuntu USN USN-6602-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6603-1 Linux kernel (AWS) vulnerabilities
Ubuntu USN Ubuntu USN USN-6604-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6604-2 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-6605-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6605-2 Linux kernel (KVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-6606-1 Linux kernel (OEM) vulnerabilities
Ubuntu USN Ubuntu USN USN-6607-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-6608-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6608-2 Linux kernel (NVIDIA) vulnerabilities
Ubuntu USN Ubuntu USN USN-6609-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6609-2 Linux kernel (NVIDIA) vulnerabilities
Ubuntu USN Ubuntu USN USN-6609-3 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-6628-1 Linux kernel (Intel IoTG) vulnerabilities
Ubuntu USN Ubuntu USN USN-6628-2 Linux kernel (Intel IoTG) vulnerabilities
Ubuntu USN Ubuntu USN USN-6635-1 Linux kernel (GCP) vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 13 Feb 2025 17:30:00 +0000

Type Values Removed Values Added
Description A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group(). We recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b. A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group(). We recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.

cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published:

Updated: 2025-02-13T17:26:59.664Z

Reserved: 2023-12-18T20:13:06.510Z

Link: CVE-2023-6931

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-12-19T14:15:08.277

Modified: 2025-02-13T18:16:11.457

Link: CVE-2023-6931

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-11-29T00:00:00Z

Links: CVE-2023-6931 - Bugzilla

cve-icon OpenCVE Enrichment

No data.