|
1 | 1 | { |
2 | 2 | "id": "EUVD-2023-59129", |
3 | 3 | "enisaUuid": "d3af44fd-bf91-3363-9f3a-15e6a5ead69d", |
4 | | - "description": "A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation.\n\nA perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group().\n\nWe recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.", |
| 4 | + "description": "A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation.\n\n\n\nA perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group().\n\n\n\nWe recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.", |
5 | 5 | "datePublished": "Dec 19, 2023, 2:09:14 PM", |
6 | | - "dateUpdated": "Feb 13, 2025, 5:26:59 PM", |
| 6 | + "dateUpdated": "Aug 17, 2026, 2:11:22 PM", |
7 | 7 | "baseScore": 7.8, |
8 | 8 | "baseScoreVersion": "3.1", |
9 | 9 | "baseScoreVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", |
10 | | - "references": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=382c27f4ed28f803b1f1473ac2d8db0afc795a1b\nhttps://kernel.dance/382c27f4ed28f803b1f1473ac2d8db0afc795a1b\nhttps://lists.debian.org/debian-lts-announce/2024/01/msg00004.html\nhttps://lists.debian.org/debian-lts-announce/2024/01/msg00005.html\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-6931\n", |
| 10 | + "references": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=382c27f4ed28f803b1f1473ac2d8db0afc795a1b\nhttps://kernel.dance/382c27f4ed28f803b1f1473ac2d8db0afc795a1b\nhttps://lists.debian.org/debian-lts-announce/2024/01/msg00004.html\nhttps://lists.debian.org/debian-lts-announce/2024/01/msg00005.html\n", |
11 | 11 | "aliases": "CVE-2023-6931\nGHSA-xv88-q3gm-mmjp\n", |
12 | 12 | "assigner": "Google", |
13 | | - "epss": 0.34, |
| 13 | + "epss": 0.72, |
14 | 14 | "enisaIdProduct": [ |
15 | 15 | { |
16 | | - "id": "2a553ef9-7d49-38b2-ac1d-18ea9528c283", |
| 16 | + "id": "1168627d-1c27-3af4-8ef2-4bc80b5061e3", |
17 | 17 | "product": { |
18 | | - "name": "Kernel" |
19 | | - } |
| 18 | + "name": "Linux kernel", |
| 19 | + "vendor": { |
| 20 | + "name": "n/a" |
| 21 | + } |
| 22 | + }, |
| 23 | + "product_version": "6.2.0 <6.6.7" |
| 24 | + }, |
| 25 | + { |
| 26 | + "id": "26c8def9-cb50-3dae-843a-8153633ea6e2", |
| 27 | + "product": { |
| 28 | + "name": "Linux kernel", |
| 29 | + "vendor": { |
| 30 | + "name": "n/a" |
| 31 | + } |
| 32 | + }, |
| 33 | + "product_version": "4.3.0 <4.19.302" |
| 34 | + }, |
| 35 | + { |
| 36 | + "id": "3932d0dd-b1ab-35b0-ab60-aed862bedc02", |
| 37 | + "product": { |
| 38 | + "name": "Linux kernel", |
| 39 | + "vendor": { |
| 40 | + "name": "n/a" |
| 41 | + } |
| 42 | + }, |
| 43 | + "product_version": "4.20.0 <5.4.264" |
| 44 | + }, |
| 45 | + { |
| 46 | + "id": "484c82e5-6840-3273-afbf-d5dab6affec7", |
| 47 | + "product": { |
| 48 | + "name": "Linux kernel", |
| 49 | + "vendor": { |
| 50 | + "name": "n/a" |
| 51 | + } |
| 52 | + }, |
| 53 | + "product_version": "5.5.0 <5.10.204" |
| 54 | + }, |
| 55 | + { |
| 56 | + "id": "643bed60-0df9-3ab9-801e-45321d60c5f0", |
| 57 | + "product": { |
| 58 | + "name": "Linux kernel", |
| 59 | + "vendor": { |
| 60 | + "name": "n/a" |
| 61 | + } |
| 62 | + }, |
| 63 | + "product_version": "5.11.0 <5.15.143" |
20 | 64 | }, |
21 | 65 | { |
22 | | - "id": "b4968a0e-5c7b-3e2b-b6ab-e61f4a1a6de1", |
| 66 | + "id": "826a79d5-b67a-32fc-9e9a-844c5bce6b07", |
23 | 67 | "product": { |
24 | | - "name": "Kernel" |
| 68 | + "name": "Linux kernel", |
| 69 | + "vendor": { |
| 70 | + "name": "n/a" |
| 71 | + } |
25 | 72 | }, |
26 | | - "product_version": "4.3 <6.7" |
| 73 | + "product_version": "5.16.0 <6.1.68" |
27 | 74 | } |
28 | 75 | ], |
29 | 76 | "enisaIdVendor": [ |
|
0 commit comments