CVE-2023-39191
An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper validation of dynamic pointers within user-supplied eBPF programs prior to executing them. This may allow an attacker with CAP_BPF privileges to escalate privileges and execute arbitrary code in the context of the kernel.
- Linux Linux Kernel
- < 6.3
- CVSS 3.1
- 8.2 HIGH
- EPSS
- 0.5% (42th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2023-10-04
CVE-2023-39191 at NVD
1 known exploit for CVE-2023-39191
Proof-of-concept code and exploit modules indexed by Sploitus