CVE-2023-46813
Incorrect access checking in the #VC handler and instruction emulation of the SEV-ES emulation of MMIO accesses could lead to arbitrary write access to kernel memory (and thus privilege escalation).
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.69%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in the Linux kernel before 6.5.9, exploitable by local users with userspace access to MMIO registers. Incorrect access checking in the #VC handler and instruction emulation of the SEV-ES emulation of MMIO accesses could lead to arbitrary write access to kernel memory (and thus privilege escalation). This depends on a race condition through which userspace can replace an instruction before the #VC handler reads it.
- CVSS 3.1
- 7.0 HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.69% probability · 51th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- cve@mitre.org
References
- https://bugzilla.suse.com/show_bug.cgi?id=1212649Issue Tracking
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.5.9Mailing List, Patch
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=63e44bc52047f182601e7817da969a105aa1f721Mailing List, Patch
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a37cd2a59d0cb270b1bba568fd3a3b8668b9d3baMailing List, Patch
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b9cb9c45583b911e0db71d09caa6b56469eb2bdfMailing List, Patch
- https://lists.debian.org/debian-lts-announce/2024/01/msg00005.html
- https://bugzilla.suse.com/show_bug.cgi?id=1212649Issue Tracking
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.5.9Mailing List, Patch
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=63e44bc52047f182601e7817da969a105aa1f721Mailing List, Patch
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a37cd2a59d0cb270b1bba568fd3a3b8668b9d3baMailing List, Patch
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b9cb9c45583b911e0db71d09caa6b56469eb2bdfMailing List, Patch
- https://lists.debian.org/debian-lts-announce/2024/01/msg00005.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.