#VU92724 Buffer overflow in Linux kernel - CVE-2023-6238
Published: June 20, 2024
Linux kernel
Linux Foundation
Description
The vulnerability allows a local privileged user to execute arbitrary code.
A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. Only privileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unrelated kernel memory, causing random kernel crashes and memory corruption.