CVE-2023-2163: Incorrect Verifier Branch Pruning Logic Leads To Arbitrary Read/Write In Linux Kernel and Lateral Privilege Escalation
Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe code paths being incorrectly marked as safe, resulting in arbitrary read/write in kernel memory, lateral privilege escalation, and container escape.
Other sources
Linux Kernel could allow a local authenticated attacker to gain elevated privileges on the system, caused by an incorrect verifier pruning in BPF subsystem. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2163?
CVE-2023-2163 has a severity rating that can lead to arbitrary read/write in kernel memory and lateral privilege escalation.
How do I fix CVE-2023-2163?
To fix CVE-2023-2163, upgrade to a kernel version higher than 6.3 or apply the specific patches provided by your Linux distribution.
Which Linux kernel versions are affected by CVE-2023-2163?
CVE-2023-2163 affects Linux Kernel versions from 5.4 up to but not including 6.3.
Can CVE-2023-2163 be exploited for container escape?
Yes, CVE-2023-2163 can potentially be exploited to escape from containers due to the privilege escalation it enables.
What components are impacted by CVE-2023-2163?
CVE-2023-2163 impacts various components including the Linux kernel and specific IBM Security Verify Governance versions.