CVE-2023-39191: Fedoraproject Fedora
High severity, CVSS 8.2. EPSS: 0.5% chance of exploitation in the next 30 days.
An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper validation of dynamic pointers within user-supplied eBPF programs prior to executing them. This may allow an attacker with CAP_BPF privileges to escalate privileges and execute arbitrary code in the context of the kernel.
Affected products
- Fedoraproject Fedora: version 38 only
- Linux Linux Kernel: from 5.19, before 6.3 (fixed in 6.3)
- Red Hat Enterprise Linux: version 9.0 only
Published 2023-10-04. Last modified 2026-06-17.