AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-39191

HIGH · CVSS 8.2 EPSS 0.52%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-10-04 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.2. It affects Linux.

CVE
CVE-2023-39191
Severity
HIGH
CVSS
8.2
EPSS
0.52%
Linux

Original NVD Description

An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper validation of dynamic pointers within user-supplied eBPF programs prior to executing them. This may allow an attacker with CAP_BPF privileges to escalate privileges and execute arbitrary code in the context of the kernel.

Related CVEs

Other vulnerabilities affecting the same vendor(s)