CVE-2023-2598
CVSS V2 None
CVSS V3 None
Description
A flaw was found in the fixed buffer registration code for io_uring (io_sqe_buffer_register in io_uring/rsrc.c) in the Linux kernel that allows out-of-bounds access to physical memory beyond the end of the buffer. This flaw enables full local privilege escalation.
Overview
- CVE ID
- CVE-2023-2598
- Assigner
- redhat
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-06-01T00:00:00
- Last Modified Date
- 2024-05-01T18:11:38.879166
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://www.openwall.com/lists/oss-security/2023/05/08/3 | |
https://security.netapp.com/advisory/ntap-20230703-0006/ | |
http://www.openwall.com/lists/oss-security/2024/04/24/3 | mailing-list |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-2598 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2598 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-24 22:13:33 | Added to TrackCVE |