CVE-2023-2235 is a use-after-free vulnerability in the Linux Kernel's Performance Events system, allowing for local privilege escalation. This high-severity flaw (CVSS 7.8) has a low attack complexity and can lead to full compromise of confidentiality, integrity, and availability. While no active exploitation or public exploit code is currently reported, and community discussion is minimal, the vulnerability affects Linux kernel versions prior to commit fd0815f632c24878e325821943edccc7fde947a2. Organizations should prioritize upgrading to patched versions to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.13, < 5.15.104CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.21CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.2.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.13, < 6.3CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.