Input validation error in Linux kernel - CVE-2023-21401
Published: November 20, 2023
Vulnerability identifier: #VU83280
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-21401
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an unspecified vulnerability in Linux kernel. A local user can execute arbitrary code with elevated privileges.
Affected software
Linux kernel
Google Android
Chrome OS
Samsung Mobile Firmware
Google Android
Chrome OS
Samsung Mobile Firmware
How to mitigate CVE-2023-21401
Install updates from vendor's website.
Samsung Mobile Firmware - update to SMR-JAN-2024
Google Android - addressed in versions 11 2023-12-05, 12L 2023-12-05, 12 2023-12-05, 13 2023-12-05, 14 2023-12-05
Chrome OS - update to 114.0.5735.339
Google Android - addressed in versions 11 2023-12-05, 12L 2023-12-05, 12 2023-12-05, 13 2023-12-05, 14 2023-12-05
Chrome OS - update to 114.0.5735.339