SB20240621109 - Integer overflow in Linux kernel perf driver
Published: June 21, 2024 Updated: May 13, 2025
Security Bulletin ID
SB20240621109
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Integer overflow (CVE-ID: CVE-2023-52797)
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to integer overflow within the pmu_sbi_ovf_handler() function in drivers/perf/riscv_pmu_sbi.c. A local user can execute arbitrary code.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2c86b24095fcf72cf51bc72d12e4350163b4e11d
- https://git.kernel.org/stable/c/45a0de41ec383c8b7c6d442734ba3852dd2fc4a7
- https://git.kernel.org/stable/c/c6e316ac05532febb0c966fa9b55f5258ed037be
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.5.13
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.3
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.7