Database/Kernel, userspace & hypervisor
Linux kernel (perf): Out-of-bounds write in perf_read_group() via read_size overflow - local root
CVSS 7.0CVE-2023-6931Kernel, userspace & hypervisorcurated
Impact
Out-of-bounds write in perf_read_group() via read_size overflow - local root
Who can reach it
Any tenant process in a container with perf access
What to do
Livepatchable; otherwise drain + reboot. Set kernel.perf_event_paranoid=3 - but note profiling access is a feature many AI tenants expect
References
Related entries
- Linux kernel (IGMP): Use-after-free in IPv4 IGMP - local privilege escalationCVE-2023-6932 · Linux kernel (IGMP)High
- Linux kernel (kTLS): splice() into a kTLS socket overwrites read-only kernel pages - local privilege escalationCVE-2024-0646 · Linux kernel (kTLS)High
- OpenSSH (sshd, RHEL9): Signal-handling race in the privsep child - possible RCE, RHEL 9 specificCVE-2024-6409 · OpenSSH (sshd, RHEL9)High
- sudo: Local privilege escalation via the `--host` option against host-specific sudoers rulesCVE-2025-32462 · sudoHigh
- glibc: Static setuid binaries incorrectly search LD_LIBRARY_PATH during dlopen - local privilege escalationCVE-2025-4802 · glibcHigh
- Xen (x86): CPU opcode cache corruption - host instability triggerable from a guestCVE-2025-54518 · Xen (x86)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.