CVE-2023-52676: bpf: Guard stack limits against 32bit overflow
bpf: Guard stack limits against 32bit overflow
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.6.14 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.7.2 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.8 - Upgrade
Upgrade
Linux kernel (bpf verifier stack bounds)to a version that resolves this vulnerability.Patch CVE-2023-52676 - Compensating control
If you use eBPF, ensure workloads that load eBPF programs are limited/controlled until the kernel fix for CVE-2023-52676 is applied, since the bug is in the bpf verifier’s stack bounds arithmetic.
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52676?
The severity of CVE-2023-52676 is considered high due to the potential for exploitation in the Linux kernel.
How do I fix CVE-2023-52676?
To fix CVE-2023-52676, upgrade your Linux kernel to versions 6.6.14, 6.7.2, 6.8, or later versions mentioned in the advisory.
What vulnerabilities are associated with CVE-2023-52676?
CVE-2023-52676 addresses a specific vulnerability in the Linux kernel related to guarding stack limits against 32-bit overflow.
Is my system affected by CVE-2023-52676?
Your system is affected by CVE-2023-52676 if you are running an impacted version of the Linux kernel as specified in the advisory.
When was CVE-2023-52676 disclosed?
CVE-2023-52676 was disclosed recently and is part of the ongoing security management process for the Linux kernel.