CVE-2023-2163: Linux Kernel
High severity, CVSS 8.8. EPSS: 3.7% chance of exploitation in the next 30 days.
Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe code paths being incorrectly marked as safe, resulting in arbitrary read/write in kernel memory, lateral privilege escalation, and container escape.
Affected products
- Linux Linux Kernel: from 5.3, before 5.4.242 (fixed in 5.4.242); from 5.5, before 5.10.179 (fixed in 5.10.179); from 5.11, before 5.15.109 (fixed in 5.15.109); from 5.16, before 6.1.26 (fixed in 6.1.26); from 6.2, before 6.2.13 (fixed in 6.2.13)
Published 2023-09-20. Last modified 2026-06-17.