[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2023-2023-422 --- kernel

ID: oval:org.secpod.oval:def:19500481Date: (C)2024-01-04   (M)2024-04-25
Class: PATCHFamily: unix




A flaw in the kernel Xen event handler can cause a deadlock with Xen console handling in unprivileged Xen guests. An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper validation of dynamic pointers within user-supplied eBPF programs prior to executing them. This may allow an attacker with CAP_BPF privileges to escalate privileges and execute arbitrary code in the context of the kernel

Platform:
Amazon Linux 2023
Product:
kernel
bpftool
python3-perf
perf
Reference:
ALAS2023-2023-422
CVE-2023-34324
CVE-2023-39191
CVE-2024-0641
CVE    3
CVE-2023-39191
CVE-2023-34324
CVE-2024-0641
CPE    4
cpe:/o:linux:linux_kernel
cpe:/a:perf:perf
cpe:/a:bpf:bpftool
cpe:/a:python:python3-perf
...

© SecPod Technologies