Kernel: udmabuf: improper validation of array index leading to local privilege escalation
Summary
| CVE | CVE-2023-2008 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-14 21:15:08 UTC |
| Updated | 2026-08-10 18:17:30 UTC |
| Description | A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler. This issue occurs due to the lack of proper validation of user-supplied data, which can result in memory access past the end of an array. This may allow an attacker to escalate privileges and execute arbitrary code in the context of the kernel. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-129 | CWE-129 Improper Validation of Array Index
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | ADP | DECLARED | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | [email protected] | Primary | 8.2 | HIGH | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 8.2 | HIGH | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Kernel | affected 4.20 5.4.202 semver | Not specified |
| CNA | Linux | Kernel | affected 5.5 5.10.127 semver | Not specified |
| CNA | Linux | Kernel | affected 5.11 5.15.51 semver | Not specified |
| CNA | Linux | Kernel | affected 5.16 5.18.8 semver | Not specified |
| CNA | Linux | Kernel | unaffected 5.19 semver | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9 | unaffected 0:5.14.0-162.6.1.el9_1 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9 | unaffected 0:5.14.0-162.6.1.rt21.168.el9_1 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9 | unaffected 0:5.14.0-162.6.1.el9_1 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | unaffected 0:5.14.0-70.58.1.el9_0 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | unaffected 0:5.14.0-70.58.1.rt21.129.el9_0 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 6 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 7 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 7 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8 | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| access.redhat.com/errata/RHSA-2022:7933 | [email protected] | access.redhat.com | |
| CVE-2023-2008 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security | af854a3a-2127-422b-91ae-364da2661108 | security.netapp.com | Third Party Advisory |
| ZDI-23-441 | Zero Day Initiative | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | Third Party Advisory, VDB Entry |
| access.redhat.com/errata/RHSA-2022:8267 | [email protected] | access.redhat.com | |
| udmabuf: add back sanity check · torvalds/linux@05b252c · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Patch |
| access.redhat.com/security/cve/CVE-2023-2008 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2023:3490 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2023:3465 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2023:3470 | [email protected] | access.redhat.com | |
| 2186862 – (CVE-2023-2008) CVE-2023-2008 kernel: udmabuf: improper validation of array index leading to local privilege escalation | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Patch, Third Party Advisory |
| Red Hat Bugzilla - 404 Object Not Found | MITRE | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2023-04-12T00:00:00.000Z | Reported to Red Hat. |
| CNA | 2023-04-13T00:00:00.000Z | Made public. |
Legacy QID Mappings
- 181858 Debian Security Update for linux (CVE-2023-2008)
- 241588 Red Hat Update for kernel (RHSA-2023:3465)
- 241590 Red Hat Update for kernel-rt (RHSA-2023:3470)
- 241591 Red Hat Update for kpatch-patch (RHSA-2023:3490)
- 673393 EulerOS Security Update for kernel (EulerOS-SA-2023-2647)
- 674113 EulerOS Security Update for kernel (EulerOS-SA-2023-2689)
- 753981 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2146-1)
- 753982 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2148-1)
- 906901 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (26280-1)
- 906974 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (26262-1)