CVE-2023-5717

Updated: 2025-08-20 02:31:42.314899

Description:

A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploited to achieve local privilege escalation. If perf_read_group() is called while an event's sibling_list is smaller than its child's sibling_list, it can increment or write to memory locations outside of the allocated buffer. We recommend upgrading past commit 32671e3799ca2e4590773fd0e63aaa4229e50c06.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.8 HIGH Released CLSA-2025:1743193221 2024-09-26 12:55:23
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2024:1722977546 2024-08-06 17:43:00
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2024:1722977984 2024-08-06 17:43:01
Ubuntu 16.04 ELS linux-hwe 4.15.0 7.8 HIGH Released CLSA-2023:1701279154 2023-11-29 13:11:48
Ubuntu 16.04 ELS linux 4.4.0 7.8 HIGH Released CLSA-2023:1701799960 2023-12-05 16:11:43
Ubuntu 18.04 ELS linux 4.15.0 7.8 HIGH Released CLSA-2023:1701265865 2023-11-29 10:10:27