U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2023-2008

Change History

CVE Modified by Red Hat, Inc. 8/10/2026 2:17:30 PM

Action Type Old Value New Value
Changed Description
A flaw was found in the Linux kernel's udmabuf device driver. The specific flaw exists within a fault handler. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an array. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the kernel.
A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler. This issue occurs due to the lack of proper validation of user-supplied data, which can result in memory access past the end of an array. This may allow an attacker to escalate privileges and execute arbitrary code in the context of the kernel.
Added CVSS V3.1

                  
                
              
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Added Reference

                  
                
              
https://access.redhat.com/errata/RHSA-2022:7933
Added Reference

                  
                
              
https://access.redhat.com/errata/RHSA-2022:8267
Added Reference

                  
                
              
https://access.redhat.com/errata/RHSA-2023:3465
Added Reference

                  
                
              
https://access.redhat.com/errata/RHSA-2023:3470
Added Reference

                  
                
              
https://access.redhat.com/errata/RHSA-2023:3490
Added Reference

                  
                
              
https://access.redhat.com/security/cve/CVE-2023-2008
Removed Reference
https://github.com/torvalds/linux/commit/05b252cccb2e5c3f56119d25de684b4f810ba4

                  
                
              
Removed Reference
https://security.netapp.com/advisory/ntap-20230517-0007/

                  
                
              
Removed Reference Type
https://github.com/torvalds/linux/commit/05b252cccb2e5c3f56119d25de684b4f810ba4 Types: Patch

                  
                
              
Removed Reference Type
https://security.netapp.com/advisory/ntap-20230517-0007/ Types: Third Party Advisory

                  
                
              
Changed Affected
[{"vendor":"n/a","product":"Linux kernel udmabuf device driver","versions":[{"version":"Fixed in kernel v5.19-rc4","status":"affected"}]}]
[{"vendor":"Linux","product":"kernel","defaultStatus":"unaffected","collectionURL":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/","packageName":"kernel","versions":[{"version":"4.20","lessThan":"5.4.202","versionType":"semver","status":"affected"},{"version":"5.5","lessThan":"5.10.127","versionType":"semver","status":"affected"},{"version":"5.11","lessThan":"5.15.51","versionType":"semver","status":"affected"},{"version":"5.16","lessThan":"5.18.8","versionType":"semver","status":"affected"},{"version":"5.19","versionType":"semver","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kernel","cpes":["cpe:/a:redhat:enterprise_linux:9::appstream","cpe:/a:redhat:enterprise_linux:9::crb","cpe:/o:redhat:enterprise_linux:9::baseos"],"versions":[{"version":"0:5.14.0-162.6.1.el9_1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kernel-rt","cpes":["cpe:/a:redhat:enterprise_linux:9::nfv","cpe:/a:redhat:enterprise_linux:9::realtime"],"versions":[{"version":"0:5.14.0-162.6.1.rt21.168.el9_1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kernel","cpes":["cpe:/a:redhat:enterprise_linux:9::appstream","cpe:/a:redhat:enterprise_linux:9::crb","cpe:/o:redhat:enterprise_linux:9::baseos"],"versions":[{"version":"0:5.14.0-162.6.1.el9_1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kernel","cpes":["cpe:/a:redhat:rhel_eus:9.0::appstream","cpe:/a:redhat:rhel_eus:9.0::crb","cpe:/o:redhat:rhel_eus:9.0::baseos"],"versions":[{"version":"0:5.14.0-70.58.1.el9_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kernel-rt","cpes":["cpe:/a:redhat:rhel_eus:9.0::nfv","cpe:/a:redhat:rhel_eus:9.0::realtime"],"versions":[{"version":"0:5.14.0-70.58.1.rt21.129.el9_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.0 Extended Update Support","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kpatch-patch","cpes":["cpe:/o:redhat:rhel_eus:9.0::baseos"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 6","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kernel","cpes":["cpe:/o:redhat:enterprise_linux:6"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kernel","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kernel-rt","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kernel","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kernel-rt","cpes":["cpe:/o:redhat:enterprise_linux:8"]}]