CVE-2023-2008
8.2
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Summary
A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler. This issue occurs due to the lack of proper validation of user-supplied data, which can result in memory access past the end of an array. This may allow an attacker to escalate privileges and execute arbitrary code in the context of the kernel.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | kernel | 4.20 < 5.4.202 | affected |
| Linux | kernel | 5.5 < 5.10.127 | affected |
| Linux | kernel | 5.11 < 5.15.51 | affected |
| Linux | kernel | 5.16 < 5.18.8 | affected |
| Linux | kernel | 5.19 | unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | 0:5.14.0-162.6.1.el9_1 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | 0:5.14.0-162.6.1.rt21.168.el9_1 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | 0:5.14.0-162.6.1.el9_1 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | 0:5.14.0-70.58.1.el9_0 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | 0:5.14.0-70.58.1.rt21.129.el9_0 < * | unaffected |
Weaknesses
- CWE-129: Improper Validation of Array Index
ADP Enrichment
CVE Program Container
Additional References
- https://github.com/torvalds/linux/commit/05b252cccb2e5c3f56119d25de684b4f810ba4
- https://www.zerodayinitiative.com/advisories/ZDI-23-441/
- https://bugzilla.redhat.com/show_bug.cgi?id=2186862
- https://security.netapp.com/advisory/ntap-20230517-0007/
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://access.redhat.com/errata/RHSA-2022:7933
- https://access.redhat.com/errata/RHSA-2022:8267
- https://access.redhat.com/errata/RHSA-2023:3465
- https://access.redhat.com/errata/RHSA-2023:3470
- https://access.redhat.com/errata/RHSA-2023:3490
- https://access.redhat.com/security/cve/CVE-2023-2008
- https://bugzilla.redhat.com/show_bug.cgi?id=2186862
- https://www.zerodayinitiative.com/advisories/ZDI-23-441/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.