UBUNTU-CVE-2023-6238
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-6238
Summary:
Details: A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. Only privileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unrelated kernel memory, causing random kernel crashes and memory corruption.
References: https://ubuntu.com/security/CVE-2023-6238, https://access.redhat.com/security/cve/CVE-2023-6238, https://lore.kernel.org/linux-nvme/[email protected]/T/#u, https://lore.kernel.org/linux-nvme/[email protected]/T/#u, https://www.cve.org/CVERecord?id=CVE-2023-6238
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/linux-hwe-edge?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
