CVE-2023-0458

Updated: 2024-11-23 03:29:31.511317

Description:

A speculative pointer dereference problem exists in the Linux Kernel on the do_prlimit() function. The resource argument value is controlled and is used in pointer arithmetic for the 'rlim' variable and can be used to leak the contents. We recommend upgrading past version 6.1.8 or commit 739790605705ddcf18f21782b9c99ad7d53a8c11


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x MEDIUM 4.7

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 4.7 MEDIUM Released CLSA-2024:1710164161 2024-03-11 09:55:20
CentOS 6 ELS kernel 2.6.32 4.7 MEDIUM Ignored 2023-05-10 03:30:19
CentOS 7 ELS kernel 3.10.0 4.7 MEDIUM Ignored 2023-09-19 05:07:24
CentOS 8.4 ELS kernel 4.18.0 4.7 MEDIUM Ignored 2024-06-24 11:36:14
CentOS 8.5 ELS kernel 4.18.0 4.7 MEDIUM Ignored 2024-06-24 11:36:14
CentOS Stream 8 ELS kernel 4.18.0 4.7 MEDIUM Ignored 2025-01-28 02:25:57
CloudLinux 6 ELS kernel 2.6.32 4.7 MEDIUM Ignored 2023-05-10 03:30:19
Oracle Linux 6 ELS kernel 2.6.32 4.7 MEDIUM Ignored 2023-05-10 05:05:13
Ubuntu 16.04 ELS linux-hwe 4.15.0 4.7 MEDIUM Released 2023-08-15 09:15:41
Ubuntu 16.04 ELS linux 4.4.0 4.7 MEDIUM Released CLSA-2023:1693333574 2023-08-29 17:07:49
Total: 11