CVE-2023-0459: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Copy_from_user on 64-bit versions of the Linux kernel does not implement the __uaccess_begin_nospec allowing a user to bypass the "access_ok" check and pass a kernel pointer to copy_from_user(). This would allow an attacker to leak information. We recommend upgrading beyond commit 74e19ef0ff8061ef55957c3abd71614ef0f42f47
Affected products
- Linux Linux Kernel: before 4.14.307 (fixed in 4.14.307); from 4.19.0, before 4.19.274 (fixed in 4.19.274); from 5.4.0, before 5.4.233 (fixed in 5.4.233); from 5.10.0, before 5.10.170 (fixed in 5.10.170); from 5.15.0, before 5.15.96 (fixed in 5.15.96); from 6.1.0, before 6.1.14 (fixed in 6.1.14); …
Published 2023-05-25. Last modified 2026-06-17.