CVE-2023-23003

Description

A NULL pointer dereference flaw was found in the Linux kernel’s Linux performance measurement and analysis tool. This flaw allows a local user to crash the system.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score44N/A
Attack VectorLocalLocalN/A
Attack ComplexityHighHighN/A
Privileges RequiredHighHighN/A
User InteractionRequiredRequiredN/A
ScopeUnchangedUnchangedN/A
ConfidentialityNoneNoneN/A
Integrity ImpactNoneNoneN/A
Availability ImpactHighHighN/A

Vector

Red Hat: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H

NVD: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H

Red Hat CVSS v3 Score Explanation

The issue is similar to the problem when already out of memory occurred and could not allocate a small amount of memory. It is very hard or impossible to use for privileges escalation, so it is only out of memory (A:H only from the CIA). Apart from this, it is hard to trigger the attack (A:H), because it would have to force out of memory and the attacker would not have control of what happens, so it cannot trigger this particular issue. The PR:H (and UI:R),is due to the problem not inside the core kernel code, but is inside the additional performance utility that has to be used by a local user to trigger the issue.

Understanding the Weakness (CWE)

Availability,Integrity

Technical Impact: Unexpected State; DoS: Crash, Exit, or Restart

An unexpected return value could place the system in a state that could lead to a crash or other unintended behaviors.

Frequently Asked Questions

Want to get errata notifications? Sign up here.