« List of all CVEs

CVE-2023-2008

Kernel: udmabuf: improper validation of array index leading to local privilege escalation

Published: 4/14/2023 Last updated: 8/10/2026 Reserved: 4/12/2023

A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler. This issue occurs due to the lack of proper validation of user-supplied data, which can result in memory access past the end of an array. This may allow an attacker to escalate privileges and execute arbitrary code in the context of the kernel.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 8.2 High CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Opam packages affected (29)

albatross cdrom conf-bpftool conf-libbpf conf-linux-libc-dev core core_unix hvsock mirage-block-unix mm ocaml-probes ortools_solvers orun rawlink rawlink-eio rawlink-lwt restricted shell solo5 solo5-bindings-hvt solo5-bindings-spt solo5-cross-aarch64 solo5-kernel-ukvm tracy-client tuntap uring vhd-format vhd-format-lwt xapi-stdext-unix

Products affected (20)

Product Vendor Version
Red Hat Enterprise Linux 9 Red Hat 21.0 ap237395
Red Hat Enterprise Linux 9.0 Extended Update Support Red Hat 21.sp1 ap348139
Red Hat Enterprise Linux 6 Red Hat n/a
Red Hat Enterprise Linux 8 Red Hat 21.0 ap344754
Red Hat Enterprise Linux 6 Red Hat 21.sp1 ap364862
Red Hat Enterprise Linux 7 Red Hat 21.sp1 ap353794
Red Hat Enterprise Linux 9.0 Extended Update Support Red Hat n/a
Red Hat Enterprise Linux 9 Red Hat n/a
kernel Linux 21.sp1 ap343790
Red Hat Enterprise Linux 9 Red Hat 21.sp1 ap359023
kernel Linux < 10.0.14393.5648
Red Hat Enterprise Linux 8 Red Hat 21.0 ap348880
Red Hat Enterprise Linux 9.0 Extended Update Support Red Hat n/a
Red Hat Enterprise Linux 7 Red Hat n/a
Red Hat Enterprise Linux 8 Red Hat n/a
Red Hat Enterprise Linux 9 Red Hat 21.sp1 ap360464
Red Hat Enterprise Linux 9.0 Extended Update Support Red Hat 21.sp1 ap346273
Red Hat Enterprise Linux 7 Red Hat 21.sp1 ap350604
Red Hat Enterprise Linux 9.0 Extended Update Support Red Hat 21.sp1 ap347889
Red Hat Enterprise Linux 9.0 Extended Update Support Red Hat n/a

References (24)