← Back

CVE-2023-0459

nvd nist
Published: May 25, 2023Modified: Jun 17, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

Copy_from_user on 64-bit versions of the Linux kernel does not implement the __uaccess_begin_nospec allowing a user to bypass the "access_ok" check and pass a kernel pointer to copy_from_user(). This would allow an attacker to leak information. We recommend upgrading beyond commit 74e19ef0ff8061ef55957c3abd71614ef0f42f47

Affected (7)

Products: Linux: Linux Kernel
1 product
Linux Kernel
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Linux
Before 4.14.307
From 4.19.0 to 4.19.274
From 5.10.0 to 5.10.170
From 5.15.0 to 5.15.96
From 5.4.0 to 5.4.233
From 6.1.0 to 6.1.14
From 6.2.0 to 6.2.1

Timeline

No history available yet.