CVE-2023-39191

CVSS v3.1 8.2 (High)
82% Progress
EPSS 0.05 % (18th)
0.05% Progress
Affected Products 3
Advisories 10
NVD Status Analyzed

An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper validation of dynamic pointers within user-supplied eBPF programs prior to executing them. This may allow an attacker with CAP_BPF privileges to escalate privileges and execute arbitrary code in the context of the kernel.

Weaknesses
CWE-20
Improper Input Validation
CWE-NVD-noinfo
CVE Status
PUBLISHED
NVD Status
Analyzed
CNA
Red Hat, Inc.
Published Date
2023-10-04 19:15:10
(11 months ago)
Updated Date
2024-08-21 18:16:34
(3 weeks ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 5.19 version and prior 6.3 version cpe:2.3:o:linux:linux_kernel >= 5.19 < 6.3

Configuration #2

    CPE23 From Up To
  Fedoraproject Fedora 38 cpe:2.3:o:fedoraproject:fedora:38

Configuration #3

    CPE23 From Up To
  Redhat Enterprise Linux 9.0 cpe:2.3:o:redhat:enterprise_linux:9.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...