CVE-2023-6931

Summary

A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation.

A perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group().

We recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux Kernel4.3.0 < 4.19.302affected
LinuxLinux Kernel4.20.0 < 5.4.264affected
LinuxLinux Kernel5.5.0 < 5.10.204affected
LinuxLinux Kernel5.11.0 < 5.15.143affected
LinuxLinux Kernel5.16.0 < 6.1.68affected
LinuxLinux Kernel6.2.0 < 6.6.7affected
LinuxLinux Kernel6.7.0unaffected
LinuxLinux Kernel382c27f4ed28f803b1f1473ac2d8db0afc795a1bunaffected

Weaknesses

  • CWE-787: CWE-787 Out-of-bounds Write

ADP Enrichment

CVE Program Container

Additional References

Additional References

References