CVE-2023-40791: Critical severity Linux Linux kernel vulnerability
extractusertosg in lib/scatterlist.c in the Linux kernel before 6.4.12 fails to unpin pages in a certain situation, as demonstrated by a WARNING for trygrabpage.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-40791?
CVE-2023-40791 is a vulnerability in the Linux kernel before version 6.4.12 that can lead to pages not being unpinned in a specific situation.
How severe is CVE-2023-40791?
CVE-2023-40791 has a severity rating of 9.1, which is considered critical.
What software is affected by CVE-2023-40791?
Linux kernel versions before 6.4.12 are affected by CVE-2023-40791.
How can I fix CVE-2023-40791?
To fix CVE-2023-40791, update the Linux kernel to version 6.4.12 or later.
Where can I find more information about CVE-2023-40791?
For more information about CVE-2023-40791, you can refer to the following links: [ChangeLog-6.4.12](https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.4.12), [Commit Details](https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f443fd5af5dbd531f880d3645d5dd36976cf087f), [Kernel Mailing List Discussion](https://lkml.org/lkml/2023/8/3/323).