← Back

CVE-2023-5717

nvd nist
Published: Oct 25, 2023Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploited to achieve local privilege escalation. If perf_read_group() is called while an event's sibling_list is smaller than its child's sibling_list, it can increment or write to memory locations outside of the allocated buffer. We recommend upgrading past commit 32671e3799ca2e4590773fd0e63aaa4229e50c06.

Affected (15)

Products: Linux: Linux Kernel
1 product
Linux Kernel
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Linux
From 3.16.50 to 3.17
From 3.2.95 to 3.3
From 4.15 to 4.19.297
From 4.20 to 5.4.259
From 4.4 to 4.14.328
From 5.11 to 5.15.137
From 5.16 to 6.1.60
From 5.5 to 5.10.199
From 6.2 to 6.5.9
Version 6.6 rc1
Version 6.6 rc2
Version 6.6 rc3
Version 6.6 rc4
Version 6.6 rc5
Version 6.6 rc6

References (8)

Source: cve-coordination@google.com
Mailing ListThird Party Advisory
Source: cve-coordination@google.com
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory

Timeline

No history available yet.