CVE-2023-5717

Updated: 2024-11-23 03:14:47.287188

Description:

A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploited to achieve local privilege escalation. If perf_read_group() is called while an event's sibling_list is smaller than its child's sibling_list, it can increment or write to memory locations outside of the allocated buffer. We recommend upgrading past commit 32671e3799ca2e4590773fd0e63aaa4229e50c06.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.8 HIGH Released CLSA-2024:1727352561 2024-09-26 12:56:27
AlmaLinux 9.2 FIPS kernel 5.14.0 7.8 HIGH Released CLSA-2024:1727351493 2024-09-26 12:55:23
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2024:1722977546 2024-08-06 17:43:00
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2024:1722977984 2024-08-06 17:43:01
Ubuntu 16.04 ELS linux-hwe 4.15.0 7.8 HIGH Released CLSA-2023:1701279154 2023-11-29 13:11:48
Ubuntu 16.04 ELS linux 4.4.0 7.8 HIGH Released CLSA-2023:1701799960 2023-12-05 16:11:43
Ubuntu 18.04 ELS linux 4.15.0 7.8 HIGH Released CLSA-2023:1701265865 2023-11-29 10:10:27