CVE-2023-21163

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Dec 4, 2023
Updated: Dec 22, 2023

Summary

CVE-2023-21163 is a newly discovered vulnerability affecting the PMR (Particular Memory Region) subsystem in the Linux kernel. The issue resides in the PMR_ReadBytes function within pmr.c, where a use-after-free condition occurs, leading to a potential arbitrary code execution. This vulnerability allows an attacker to escalate privileges locally in the kernel without requiring any additional execution privileges. Importantly, user interaction is not necessary for exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share