Vulnerability Description
Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe code paths being incorrectly marked as safe, resulting in arbitrary read/write in kernel memory, lateral privilege escalation, and container escape.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.3, < 5.4.242 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=71Mailing ListPatch
- https://bughunters.google.com/blog/6303226026131456/a-deep-dive-into-cve-2023-21
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=71Mailing ListPatch
FAQ
What is CVE-2023-2163?
CVE-2023-2163 is a vulnerability with a CVSS score of 10.0 (CRITICAL). Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe code paths being incorrectly marked as safe, resulting in arbitrary read/write in kernel memory, lateral privilege escalation, a...
How severe is CVE-2023-2163?
CVE-2023-2163 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-2163?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.