CVE-2023-2008

Summary

A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler. This issue occurs due to the lack of proper validation of user-supplied data, which can result in memory access past the end of an array. This may allow an attacker to escalate privileges and execute arbitrary code in the context of the kernel.

Affected Software

VendorProductVersion RangeStatus
Linuxkernel4.20 < 5.4.202affected
Linuxkernel5.5 < 5.10.127affected
Linuxkernel5.11 < 5.15.51affected
Linuxkernel5.16 < 5.18.8affected
Linuxkernel5.19unaffected
Red HatRed Hat Enterprise Linux 90:5.14.0-162.6.1.el9_1 < *unaffected
Red HatRed Hat Enterprise Linux 90:5.14.0-162.6.1.rt21.168.el9_1 < *unaffected
Red HatRed Hat Enterprise Linux 90:5.14.0-162.6.1.el9_1 < *unaffected
Red HatRed Hat Enterprise Linux 9.0 Extended Update Support0:5.14.0-70.58.1.el9_0 < *unaffected
Red HatRed Hat Enterprise Linux 9.0 Extended Update Support0:5.14.0-70.58.1.rt21.129.el9_0 < *unaffected

Weaknesses

  • CWE-129: Improper Validation of Array Index

ADP Enrichment

CVE Program Container

Additional References

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References