CVE-2023-50431: Medium severity linux kernel vulnerability
Last updated 29 November 2024
Other sources
secattestinfo in drivers/accel/habanalabs/common/habanalabsioctl.c in the Linux kernel through 6.6.5 allows an information leak to user space because info->pad0 is not initialized.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50431?
CVE-2023-50431 has a medium severity rating due to the potential information leak that could expose sensitive information to user space.
How do I fix CVE-2023-50431?
To fix CVE-2023-50431, upgrade to a version of the Linux Kernel newer than 6.6.5, specifically versions such as 5.10.227 or later.
What software is affected by CVE-2023-50431?
CVE-2023-50431 affects the Linux Kernel version 6.6.5 and earlier versions, including specific Debian packages.
What is the nature of the vulnerability in CVE-2023-50431?
CVE-2023-50431 involves an uninitialized variable in the sec_attest_info structure that can lead to an information leak.
Has CVE-2023-50431 been patched?
Yes, CVE-2023-50431 has been addressed in subsequent kernel releases after the identified vulnerability.