UBUNTU-CVE-2023-21102
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-21102
UBUNTU-CVE-2023-21102
Summary:
Details: In __efi_rt_asm_wrapper of efi-rt-wrapper.S, there is a possible bypass of shadow stack protection due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-260821414References: Upstream kernel
References: https://ubuntu.com/security/CVE-2023-21102, https://source.android.com/docs/security/bulletin/2023-05-01, https://git.kernel.org/linus/ff7a167961d1b97e0e205f245f806e564d3505e7, https://git.kernel.org/linus/18bba1843fc7f264f58c9345d00827d082f9c558, https://ubuntu.com/security/notices/USN-6079-1, https://ubuntu.com/security/notices/USN-6091-1, https://ubuntu.com/security/notices/USN-6096-1, https://ubuntu.com/security/notices/USN-6134-1, https://www.cve.org/CVERecord?id=CVE-2023-21102
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/[email protected]~16.04.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
