CVE-2023-6931: Out-of-bounds write in Linux kernel's Performance Events system component

Published Dec 4, 2023
·
Updated

A flaw was found in the Linux kernel. It is possible to overflow a perfevent's readsize, causing an out-of-bounds write in perfreadgroup(). The check meant to prevent such an overflow in perfeventvalidatesize() does not account for groups of events with mixed readformat values. The flaw can be triggered with events created with PERFFORMATGROUP or events added with PERFFORMATGROUP after some preconditions.

The bug was introduced around fa8c269353d5 ("perf/core: Invert perfreadgroup() loops"). Fixes: a723968c0ed3 ("perf: Fix u16 overflows").

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=382c27f4ed28f803b1f1473ac2d8db0afc795a1b

Other sources

A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation.

A perfevent's readsize can overflow, leading to an heap out-of-bounds increment or write in perfreadgroup().

We recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.

MITRE

Linux Kernel could allow a local authenticated attacker to gain elevated privileges on the system, caused by a heap out-of-bounds write flaw in the Performance Events system component. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges.

IBM

Affected Software

4 affected componentsFixes available
IBM QRadar SIEM<=7.5 - 7.5.0 UP8 IF01
Linux Linux kernel>=4.3<6.7
Debian Debian Linux=10.0
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.22-16.12.25-1

Event History

Dec 4, 2023
Data Sourced
via Red Hat·11:03 AM
DescriptionSeverityAffected Software
Dec 19, 2023
CVE Published
via MITRE·02:09 PM
Data Sourced
via MITRE·02:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 25, 2024
Data Sourced
via Launchpad·10:39 PM
Description
May 4, 2025
Data Sourced
via Ubuntu·11:51 PM
RemedyDescriptionSeverityAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-6931?

CVE-2023-6931 has been classified as a medium severity vulnerability affecting the Linux kernel.

2

How do I fix CVE-2023-6931?

To fix CVE-2023-6931, upgrade to a patched version of the Linux kernel that addresses this specific vulnerability.

3

What versions of the Linux kernel are affected by CVE-2023-6931?

CVE-2023-6931 affects Linux kernel versions from 4.3 up to, but not including, version 6.7.

4

Which distributions are impacted by CVE-2023-6931?

Distributions such as Debian 10.0 and IBM QRadar SIEM versions up to 7.5.0 UP8 IF01 are impacted by CVE-2023-6931.

5

What is the impact of CVE-2023-6931?

CVE-2023-6931 can lead to an out-of-bounds write in perf_read_group(), potentially allowing for unauthorized actions by an attacker.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203