cert-portal.siemens.com
https://cert-portal.siemens.com/productcert/html/ssa-265688.html CVE-2023-6931
HIGH
Out-of-bounds write in Linux kernel's Performance Events system component
Record summary
CVE-2023-6931 has a selected CVSS score of 7.8 (high); EIP currently links 1 repository PoC.
Description
A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group(). We recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
Affected products and versions
8| Product | Source | Version range | Status |
|---|---|---|---|
KernelBrowse Linux / KernelDefault status: unaffected | CVE List | 4.3 to < 6.7 | affected |
RUGGEDCOM RST2428PBrowse Siemens / RUGGEDCOM RST2428PDefault status: unknown | CVE List | Before * | unaffected |
SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 familyBrowse Siemens / SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 familyDefault status: unknown | CVE List | Before * | unaffected |
SCALANCE XCM-/XRM-/XCH-/XRH-300 familyBrowse Siemens / SCALANCE XCM-/XRM-/XCH-/XRH-300 familyDefault status: unknown | CVE List | Before * | unaffected |
SIMATIC S7-1500 CPU 1518-4 PN/DP MFPBrowse Siemens / SIMATIC S7-1500 CPU 1518-4 PN/DP MFPDefault status: unknown | CVE List | V3.1.0 to < V3.1.5 | affected |
SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPBrowse Siemens / SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPDefault status: unknown | CVE List | V3.1.0 to < V3.1.5 | affected |
SIMATIC S7-1500 TM MFP - GNU/Linux subsystemBrowse Siemens / SIMATIC S7-1500 TM MFP - GNU/Linux subsystemDefault status: unknown | CVE List | Before * | affected |
SIPLUS S7-1500 CPU 1518-4 PN/DP MFPBrowse Siemens / SIPLUS S7-1500 CPU 1518-4 PN/DP MFPDefault status: unknown | CVE List | V3.1.0 to < V3.1.5 | affected |
Proofs of concept
1Repository PoCs
GitHubK0n9-log/CVE-2023-6931Repository PoCby K0n9-logStars: 2Not analyzed3 files
References
9cert-portal.siemens.com
https://cert-portal.siemens.com/productcert/html/ssa-398330.html cert-portal.siemens.com
https://cert-portal.siemens.com/productcert/html/ssa-613116.html cert-portal.siemens.com
https://cert-portal.siemens.com/productcert/html/ssa-794697.html git.kernel.orgpatch
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit?id=382c27f4ed28f803b1f1473ac2d8db0afc795a1b kernel.dance
https://kernel.dance/382c27f4ed28f803b1f1473ac2d8db0afc795a1b lists.debian.org
https://lists.debian.org/debian-lts-announce/2024/01/msg00004.html lists.debian.org
https://lists.debian.org/debian-lts-announce/2024/01/msg00005.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-6931