Record summary

CVE-2023-6931 has a selected CVSS score of 7.8 (high); EIP currently links 1 repository PoC.

Description

A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group(). We recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

Affected products and versions

8
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List4.3 to < 6.7affected

Default status: unknown

CVE ListBefore *unaffected

SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family

Browse Siemens / SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family

Default status: unknown

CVE ListBefore *unaffected

SCALANCE XCM-/XRM-/XCH-/XRH-300 family

Browse Siemens / SCALANCE XCM-/XRM-/XCH-/XRH-300 family

Default status: unknown

CVE ListBefore *unaffected

SIMATIC S7-1500 CPU 1518-4 PN/DP MFP

Browse Siemens / SIMATIC S7-1500 CPU 1518-4 PN/DP MFP

Default status: unknown

CVE ListV3.1.0 to < V3.1.5affected

SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP

Browse Siemens / SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP

Default status: unknown

CVE ListV3.1.0 to < V3.1.5affected

SIMATIC S7-1500 TM MFP - GNU/Linux subsystem

Browse Siemens / SIMATIC S7-1500 TM MFP - GNU/Linux subsystem

Default status: unknown

CVE ListBefore *affected

SIPLUS S7-1500 CPU 1518-4 PN/DP MFP

Browse Siemens / SIPLUS S7-1500 CPU 1518-4 PN/DP MFP

Default status: unknown

CVE ListV3.1.0 to < V3.1.5affected

Proofs of concept

1

Repository PoCs

GitHubK0n9-log/CVE-2023-6931Repository PoCby K0n9-logStars: 2Not analyzed3 files

893.8 KiB

GitHub

PoC details

References

9