CVE-2023-2163

Aliases:UBUNTU-CVE-2023-2163DEBIAN-CVE-2023-2163
Advisory lineage Upstream: 0 Downstream: 63
Modified
Published: 20 Sept 2023, 05:02
Last modified:27 Feb 2025, 20:49

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
10 CRITICAL
v3.1 (cve.org)
EPSS Score
3.67% LOW
4% probability +3.50%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

20 Sept 2023, 05:02
Published
Vulnerability first disclosed
27 Feb 2025, 20:49
Last Modified
Vulnerability information updated

Description

Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe code paths being incorrectly marked as safe, resulting in arbitrary read/write in kernel memory, lateral privilege escalation, and container escape.

CVSS Metrics

  • v3.1CRITICALScore: 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
  • v3.1HIGHScore: 8.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 3.67% Percentile: 89%

Techniques & Countermeasures

  • CWE-682Incorrect Calculation

    The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.

Affected Systems

  • debianlinux

    < 5.10.179-1 | < 6.1.27-1 | < 6.1.27-1 | < 6.1.27-1

  • ubuntulinux

    < 5.4.0-162.179 | < 5.15.0-79.86

  • ubuntulinux-allwinner-5.19

    all

  • ubuntulinux-aws

    < 5.4.0-1109.118 | < 5.15.0-1042.47

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    all

  • ubuntulinux-aws-5.15

    < 5.15.0-1041.46~20.04.1

  • ubuntulinux-aws-5.19

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    < 5.4.0-1109.118~18.04.1

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-6.2

    < 6.2.0-1007.7~22.04.1

  • ubuntulinux-aws-fips

    < 5.4.0-1109.118+fips1 | all

  • ubuntulinux-azure

    all | < 5.4.0-1115.122 | < 5.15.0-1045.52

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    all

  • ubuntulinux-azure-5.15

    < 5.15.0-1045.52~20.04.1

  • ubuntulinux-azure-5.19

    all

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    < 5.4.0-1115.122~18.04.1

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde

    all | < 5.15.0-1044.51.1

  • ubuntulinux-azure-fde-5.19

    all

  • ubuntulinux-azure-fips

    < 5.4.0-1115.122+fips1 | all

  • ubuntulinux-bluefield

    all | < 5.4.0-1070.76 | < 5.15.0-1022.24

  • ubuntulinux-fips

    < 5.4.0-1084.93 | all

  • ubuntulinux-gcp

    all | < 5.4.0-1112.121 | < 5.15.0-1039.47

  • ubuntulinux-gcp-5.11

    all

  • ubuntulinux-gcp-5.13

    all

  • ubuntulinux-gcp-5.15

    < 5.15.0-1039.47~20.04.1

  • ubuntulinux-gcp-5.19

    all

  • ubuntulinux-gcp-5.3

    all

  • ubuntulinux-gcp-5.4

    < 5.4.0-1112.121~18.04.1

  • ubuntulinux-gcp-5.8

    all

  • ubuntulinux-gcp-fips

    < 5.4.0-1112.121+fips1 | all

  • ubuntulinux-gke

    all | < 5.15.0-1039.44

  • ubuntulinux-gke-4.15

    all

  • ubuntulinux-gke-5.15

    < 5.15.0-1039.44~20.04.1

  • ubuntulinux-gke-5.4

    all

  • ubuntulinux-gkeop

    < 5.4.0-1076.80 | < 5.15.0-1025.30

  • ubuntulinux-gkeop-5.15

    < 5.15.0-1025.30~20.04.1

  • ubuntulinux-gkeop-5.4

    all

  • ubuntulinux-hwe

    all

  • ubuntulinux-hwe-5.11

    all

  • ubuntulinux-hwe-5.13

    all

  • ubuntulinux-hwe-5.15

    < 5.15.0-79.86~20.04.2

  • ubuntulinux-hwe-5.19

    all

  • ubuntulinux-hwe-5.4

    < 5.4.0-162.179~18.04.1

Showing first 50 affected entries in server-rendered view.

References (16)