Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-23523

16
FAUCET Score

CVE-2022-23523 is a medium-severity vulnerability affecting the linux-loader crate in versions prior to 0.8.1, where malicious ELF header modifications in a kernel image could cause Virtual Machine Monitors using the crate to enter an infinite loop. This local attack, requiring low privileges and complexity, can lead to a denial of service (availability impact). There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.8.1CPE matchmatch criteria
cpe:2.3:a:linux-loader_project:linux-loader:*:*:*:*:*:rust:*:*

CVSS Data

CVSS version used by this source: 3.1

4.0MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
2.5
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
10.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0021 is in the 51st percentile among its peer group of 15,938 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 17679-17084Fixed in: 3.2.0.azl2-3
microsoftpatch availablevia msrc
Product: 19706-17084Fixed in: 3.2.0.azl2-3
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 3.2.0.azl2-3
microsoftpatch availablevia msrc
Product: azl3 kata-containers 3.2.0.azl2-3 on Azure Linux 3.0Fixed in: 3.2.0.azl2-3
microsoftpatch availablevia msrc
Product: azl3 kata-containers 3.1.3-2 on Azure Linux 3.0Fixed in: 3.2.0.azl2-3
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 3.2.0.azl2-3
rustpatch availablevia ghsa
Product: linux-loaderFixed in: 0.8.1

Vendor Advisories (3)

microsoft2024-Sep/CVE-2022-23523

CVE-2022-23523

Sep 10, 2024
microsoft2022-Dec/CVE-2022-23523Moderate

rust-vmm linux-loader vulnerable to Out-of-bounds Read

Dec 13, 2022
rustGHSA-52h2-m2cf-9jh6low

linux-loader reading beyond EOF could lead to infinite loop

Dec 12, 2022

References

github.com / rust-vmm/linux-loader/pull/125
Issue TrackingPatchThird Party Advisory
github.com / rust-vmm/linux-loader/security/advisories/GHSA-52h2-m2cf-9jh6
Issue TrackingThird Party Advisory