Junglewise Threat Intelligence

CVE-2023-6931: Linux Kernel heap out-of-bounds write in Performance Events

CVE-2023-6931 · Severity: high · CVSS 7.8 · Published 2023-12-19

Technologies: Debian Linux, Linux Kernel. Vendors: Debian, Linux.

Executive brief

A security vulnerability has been identified in the Linux kernel's performance monitoring component, which is used to track system hardware and software events. A local user with basic access to the system could exploit this flaw to gain full administrative (root) privileges. This could allow an attacker to bypass security controls, access sensitive data, or disrupt system operations.

Technical details

A heap out-of-bounds write vulnerability exists in the Linux kernel's Performance Events (perf) subsystem. The root cause is an integer overflow in the 'read_size' calculation within 'perf_read_group()', where the kernel fails to properly validate the size of event groups when multiple events have different read formats. A local attacker with low privileges can trigger this overflow to cause a heap out-of-bounds increment or write. This can lead to a denial of service (system crash) or local privilege escalation to root. The vulnerability is mitigated on some systems (like Debian) by restrictive 'kernel.perf_event_paranoid' sysctl settings. A fix is available in kernel commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.

Affected products

  • Linux Linux Kernel 4.3 to 6.7

Timeline

  • 2023-11-29: patched: Fix committed to Linux stable tree
  • 2023-12-19: disclosed: CVE published by Google Inc.
  • 2024-01-11: advisory: Debian LTS advisory published

References

Related threats