First published: Thu Jun 01 2023(Updated: )
A flaw was found in the fixed buffer registration code for io_uring (io_sqe_buffer_register in io_uring/rsrc.c) in the Linux kernel that allows out-of-bounds access to physical memory beyond the end of the buffer. This flaw enables full local privilege escalation.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | >=6.3<6.3.2 | |
Netapp Hci Baseboard Management Controller | =h300s | |
Netapp Hci Baseboard Management Controller | =h410c | |
Netapp Hci Baseboard Management Controller | =h410s | |
Netapp Hci Baseboard Management Controller | =h500s | |
Netapp Hci Baseboard Management Controller | =h700s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this flaw is CVE-2023-2598.
The severity level of CVE-2023-2598 is high (7.8).
The Linux Kernel and Netapp HCI Baseboard Management Controller (h300s, h410c, h410s, h500s, h700s) are affected by CVE-2023-2598.
CVE-2023-2598 allows for full local privilege escalation.
Yes, there are references available for CVE-2023-2598: https://www.openwall.com/lists/oss-security/2023/05/08/3 and https://security.netapp.com/advisory/ntap-20230703-0006/