cve/2023/CVE-2023-2163.md
2024-08-12 19:01:27 +00:00

27 lines
1.1 KiB
Markdown
Raw Blame History

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

### [CVE-2023-2163](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2163)
![](https://img.shields.io/static/v1?label=Product&message=Linux%20Kernel&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-682%20Incorrect%20Calculation&color=brighgreen)
### Description
Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafecode paths being incorrectly marked as safe, resulting in arbitrary read/write inkernel memory, lateral privilege escalation, and container escape.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/Dikens88/hopp
- https://github.com/Snoopy-Sec/Localroot-ALL-CVE
- https://github.com/aobakwewastaken/aobakwewastaken
- https://github.com/carmilea/carmilea
- https://github.com/google/buzzer
- https://github.com/google/security-research
- https://github.com/kherrick/hacker-news
- https://github.com/kherrick/lobsters
- https://github.com/phixion/phixion
- https://github.com/shannonmullins/hopp