CVE-2023-31084
Published on: Not Yet Published
Last Modified on: 08/19/2023 06:16:00 PM UTC
Certain versions of Linux Kernel from Linux contain the following vulnerability:
An issue was discovered in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel 6.2. There is a blocking operation when a task is in !TASK_RUNNING. In dvb_frontend_get_event, wait_event_interruptible is called; the condition is dvb_frontend_test_event(fepriv,events). In dvb_frontend_test_event, down(&fepriv->sem) is called. However, wait_event_interruptible would put the process to sleep, and down(&fepriv->sem) may block the process.
- CVE-2023-31084 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 5.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
[SECURITY] Fedora 38 Update: kernel-6.3.7-200.fc38 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
[SECURITY] [DLA 3508-1] linux security update | lists.debian.org text/html |
![]() |
[SECURITY] Fedora 37 Update: kernel-6.3.7-100.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
Debian -- Security Information -- DSA-5480-1 linux | www.debian.org Depreciated Link text/html |
![]() |
Debian -- Security Information -- DSA-5448-1 linux | www.debian.org Depreciated Link text/html |
![]() |
BUG: WARNING in dvb_frontend_get_event - Yu Hao | lore.kernel.org text/html |
![]() |
Related QID Numbers
- 160818 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2023-12688)
- 199469 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6231-1)
- 284026 Fedora Security Update for kernel (FEDORA-2023-4426b7005f)
- 284061 Fedora Security Update for kernel (FEDORA-2023-75b22000cd)
- 390286 Oracle Managed Virtualization (VM) Server for x86 Security Update for kernel (OVMSA-2023-0018)
- 673272 EulerOS Security Update for kernel (EulerOS-SA-2023-2584)
- 754097 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2507-1)
- 754105 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2537-1)
- 754106 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2534-1)
- 754110 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2538-1)
- 754120 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2611-1)
- 754145 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2651-1)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Linux | Linux Kernel | 6.2 | All | All | All |
- cpe:2.3:o:linux:linux_kernel:6.2:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-31084 : An issue was discovered in drivers/media/dvb-core/dvb_frontend.c in the #Linux #kernel 6.2. There… twitter.com/i/web/status/1… | 2023-04-24 06:08:45 |