Out-of-bounds write in procps - CVE-2023-4016

 

Out-of-bounds write in procps - CVE-2023-4016

Published: August 15, 2023


Vulnerability identifier: #VU79561
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-4016
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error when processing untrusted input. A local user can trigger an out-of-bounds write and execute arbitrary code with elevated privileges.


Affected software

procps
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
Oracle Linux
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
Anolis OS
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Fedora
OpenShift Pipelines
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
Oracle Communications Cloud Native Core Binding Support Function
IBM MQ Operator
APEX Cloud Platform for Red Hat OpenShift
App Connect Enterprise Certified Container
Red Hat Migration Toolkit for Applications
IBM Sterling Connect:Direct for UNIX
IBM Security Verify Governance
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
OpenShift Virtualization
Red Hat Single Sign-On
webMethods Managed File Transfer
ObjectScale
APEX Cloud Platform for Microsoft Azure
IBM Cloud Pak for Watson AIOps
Storage Resource Manager
IBM Sterling Order Management
Dell PowerProtect Cyber Recovery
Oracle Communications Cloud Native Core Policy
procps (Ubuntu package)
libprocps3-debuginfo
procps-devel
procps-debuginfo
procps-debugsource
procps
libprocps3
procps-ng (Red Hat package)
procps-ng
procps-ng-doc
procps-ng-i18n
libprocps7
libprocps7-debuginfo
procps-ng-help
procps-ng-debuginfo
procps-ng-debugsource
procps-ng-devel
procps-lang
libprocps8
libprocps8-debuginfo
SmartFabric Manager
Red Hat OpenShift GitOps
Dell EMC Storage Monitoring and Reporting (SMR)
RecoverPoint for VMs
Dell EMC VxRail Appliance

How to mitigate CVE-2023-4016

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.4
OpenShift Pipelines - update to 1.10.6
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 3.74.8, 4.1.6, 4.3.1
OpenShift Virtualization - addressed in versions 4.12.9, 4.13.6, 4.14.1
OpenShift Logging - addressed in versions 5.7.10, 5.8.1
Red Hat Single Sign-On - update to 7.6.6
procps (Ubuntu package) - addressed in versions Ubuntu Pro, 2:3.3.16-1ubuntu2.4, 2:3.3.17-6ubuntu2.1, 2:4.0.3-1ubuntu1.23.04.1, 2:4.0.3-1ubuntu1.23.10.1
SmartFabric Manager - update to 1.3.0
ObjectScale - update to 1.4.0
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
Red Hat OpenShift GitOps - addressed in versions 1.12.5, 1.13.1
IBM MQ Operator - addressed in versions 2.0.17, 3.0.0
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
libprocps3-debuginfo - addressed in versions 3.3.9-11.27.1, 3.3.9-11.33.1
procps-devel - addressed in versions 3.3.9-11.27.1, 3.3.9-11.33.1, 3.3.15-150000.7.34.1, 3.3.17-150000.7.42.1
procps-debuginfo - addressed in versions 3.3.9-11.27.1, 3.3.9-11.33.1, 3.3.15-150000.7.34.1, 3.3.17-150000.7.42.1
procps-debugsource - addressed in versions 3.3.9-11.27.1, 3.3.9-11.33.1, 3.3.15-150000.7.34.1, 3.3.17-150000.7.42.1
procps - addressed in versions 3.3.9-11.27.1, 3.3.9-11.33.1, 3.3.15-150000.7.34.1, 3.3.17-150000.7.42.1
libprocps3 - addressed in versions 3.3.9-11.27.1, 3.3.9-11.33.1
procps-ng (Red Hat package) - addressed in versions 3.3.15-14.el8, 3.3.17-13.el9
procps-ng - addressed in versions 3.3.15-14.0.1, 3.3.17-5
procps-ng-doc - addressed in versions 3.3.15-14.0.1, 3.3.17-5
procps-ng-i18n - addressed in versions 3.3.15-14.0.1, 3.3.17-5
libprocps7 - update to 3.3.15-150000.7.34.1
libprocps7-debuginfo - update to 3.3.15-150000.7.34.1
procps-ng-i18n - update to 3.3.16-19
procps-ng-help - update to 3.3.16-19
procps-ng-debuginfo - update to 3.3.16-19
procps-ng-debugsource - update to 3.3.16-19
procps-ng-devel - update to 3.3.16-19
procps-ng - update to 3.3.16-19
procps-ng-devel - update to 3.3.17-5
procps-ng - update to 3.3.17-11.fc38
procps-lang - update to 3.3.17-150000.7.42.1
libprocps8 - update to 3.3.17-150000.7.42.1
libprocps8-debuginfo - update to 3.3.17-150000.7.42.1
IBM Cloud Pak for Watson AIOps - update to 4.4.1
Red Hat OpenShift Container Platform - addressed in versions 4.13.45, 4.14.32, 4.14.33
Dell EMC Storage Monitoring and Reporting (SMR) - addressed in versions 5.0.2.2, 5.1.0.0
Storage Resource Manager - addressed in versions 5.0.2.2, 5.1.0.0
App Connect Enterprise Certified Container - addressed in versions 5.0.14, 11.2.0
RecoverPoint for VMs - update to 6.0.SP1.P1
Red Hat Migration Toolkit for Applications - update to 6.2
IBM Sterling Connect:Direct for UNIX - update to 6.3.0.1
Dell EMC VxRail Appliance - update to 8.0.120
IBM Security Verify Governance - update to 10.0.2.0.4
IBM Sterling Order Management - update to 10.0.2403.1
Dell PowerProtect Cyber Recovery - update to 19.15.0.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF035, 21.0.3.30, 23.0.2.2, 24.0.0-IF001
IBM Automation Decision Services - update to 23.0.2.0.2

External References

Related Security Bulletins