UBUNTU-CVE-2023-1077
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-1077
UBUNTU-CVE-2023-1077
Summary:
Details: In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not detected by the BUG_ON condition, as the confused entry will not be NULL, but list_head.The buggy error condition would lead to a type confused entry with the list head,which would then be used as a type confused sched_rt_entity,causing memory corruption.
References: https://ubuntu.com/security/CVE-2023-1077, https://git.kernel.org/linus/7c4a5b89a0b5a57a64b601775b296abf77a9fe97, https://seclists.org/oss-sec/2023/q1/126, https://ubuntu.com/security/notices/USN-6033-1, https://ubuntu.com/security/notices/USN-6171-1, https://ubuntu.com/security/notices/USN-6172-1, https://ubuntu.com/security/notices/USN-6185-1, https://ubuntu.com/security/notices/USN-6187-1, https://ubuntu.com/security/notices/USN-6207-1, https://ubuntu.com/security/notices/USN-6222-1, https://ubuntu.com/security/notices/USN-6223-1, https://ubuntu.com/security/notices/USN-6256-1, https://www.cve.org/CVERecord?id=CVE-2023-1077
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
