Unrated severityNVD Advisory· Published Oct 27, 2023· Updated Feb 25, 2026
CVE-2023-46813
CVE-2023-46813
Description
An issue was discovered in the Linux kernel before 6.5.9, exploitable by local users with userspace access to MMIO registers. Incorrect access checking in the #VC handler and instruction emulation of the SEV-ES emulation of MMIO accesses could lead to arbitrary write access to kernel memory (and thus privilege escalation). This depends on a race condition through which userspace can replace an instruction before the #VC handler reads it.
Affected products
97- Linux/Linux kerneldescription
- osv-coords96 versionspkg:deb/ubuntu/linux-azure@6.5.0-1015.15?arch=source&distro=manticpkg:rpm/almalinux/bpftoolpkg:rpm/almalinux/kernelpkg:rpm/almalinux/kernel-abi-stablelistspkg:rpm/almalinux/kernel-corepkg:rpm/almalinux/kernel-cross-headerspkg:rpm/almalinux/kernel-debugpkg:rpm/almalinux/kernel-debug-corepkg:rpm/almalinux/kernel-debug-develpkg:rpm/almalinux/kernel-debug-modulespkg:rpm/almalinux/kernel-debug-modules-extrapkg:rpm/almalinux/kernel-develpkg:rpm/almalinux/kernel-docpkg:rpm/almalinux/kernel-modulespkg:rpm/almalinux/kernel-modules-extrapkg:rpm/almalinux/kernel-toolspkg:rpm/almalinux/kernel-tools-libspkg:rpm/almalinux/kernel-tools-libs-develpkg:rpm/almalinux/kernel-zfcpdumppkg:rpm/almalinux/kernel-zfcpdump-corepkg:rpm/almalinux/kernel-zfcpdump-develpkg:rpm/almalinux/kernel-zfcpdump-modulespkg:rpm/almalinux/kernel-zfcpdump-modules-extrapkg:rpm/almalinux/perfpkg:rpm/almalinux/python3-perfpkg:rpm/opensuse/dtb-aarch64&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/kernel-64kb&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/kernel-azure&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/kernel-azure&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/kernel-debug&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/kernel-default-base&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/kernel-default&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/kernel-docs&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/kernel-kvmsmall&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/kernel-obs-build&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/kernel-obs-qa&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/kernel-rt_debug&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/kernel-rt_debug&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/kernel-rt&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/kernel-rt&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/kernel-rt&distro=openSUSE%20Leap%20Micro%205.3pkg:rpm/opensuse/kernel-rt&distro=openSUSE%20Leap%20Micro%205.4pkg:rpm/opensuse/kernel-source-azure&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/kernel-source-azure&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-source-rt&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/kernel-source-rt&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/kernel-syms-azure&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/kernel-syms-azure&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/kernel-syms&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/kernel-syms-rt&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/kernel-syms-rt&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/kernel-zfcpdump&distro=openSUSE%20Leap%2015.5pkg:rpm/suse/kernel-64kb&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/kernel-azure&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP4pkg:rpm/suse/kernel-azure&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP5pkg:rpm/suse/kernel-default-base&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/kernel-default-base&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP5pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP5pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2015%20SP5pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP5pkg:rpm/suse/kernel-docs&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP5pkg:rpm/suse/kernel-livepatch-SLE15-SP4-RT_Update_15&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP4pkg:rpm/suse/kernel-livepatch-SLE15-SP4_Update_11&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP4pkg:rpm/suse/kernel-livepatch-SLE15-SP5-RT_Update_0&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP5pkg:rpm/suse/kernel-livepatch-SLE15-SP5-RT_Update_1&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP5pkg:rpm/suse/kernel-livepatch-SLE15-SP5-RT_Update_5&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP5pkg:rpm/suse/kernel-livepatch-SLE15-SP5-RT_Update_8&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP5pkg:rpm/suse/kernel-livepatch-SLE15-SP5_Update_0&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP5pkg:rpm/suse/kernel-livepatch-SLE15-SP5_Update_2&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP5pkg:rpm/suse/kernel-livepatch-SLE15-SP5_Update_5&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP5pkg:rpm/suse/kernel-livepatch-SLE15-SP5_Update_7&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP5pkg:rpm/suse/kernel-obs-build&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP5pkg:rpm/suse/kernel-rt_debug&distro=SUSE%20Real%20Time%20Module%2015%20SP4pkg:rpm/suse/kernel-rt_debug&distro=SUSE%20Real%20Time%20Module%2015%20SP5pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/kernel-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP4pkg:rpm/suse/kernel-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP5pkg:rpm/suse/kernel-source-azure&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP4pkg:rpm/suse/kernel-source-azure&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP5pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP5pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP4pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP5pkg:rpm/suse/kernel-syms-azure&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP4pkg:rpm/suse/kernel-syms-azure&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP5pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP5pkg:rpm/suse/kernel-syms-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP4pkg:rpm/suse/kernel-syms-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP5pkg:rpm/suse/kernel-zfcpdump&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5
< 6.5.0-1015.15+ 95 more
- (no CPE)range: < 6.5.0-1015.15
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 4.18.0-513.18.1.el8_9
- (no CPE)range: < 5.14.21-150500.55.36.1
- (no CPE)range: < 5.14.21-150500.55.36.1
- (no CPE)range: < 5.14.21-150400.14.72.1
- (no CPE)range: < 5.14.21-150500.33.23.1
- (no CPE)range: < 5.14.21-150500.55.36.1
- (no CPE)range: < 5.14.21-150500.55.36.1.150500.6.15.3
- (no CPE)range: < 5.14.21-150500.55.36.1
- (no CPE)range: < 5.14.21-150500.55.36.1
- (no CPE)range: < 5.14.21-150500.55.36.1
- (no CPE)range: < 5.14.21-150500.55.36.1
- (no CPE)range: < 5.14.21-150500.55.36.1
- (no CPE)range: < 5.14.21-150400.15.59.1
- (no CPE)range: < 5.14.21-150500.13.27.2
- (no CPE)range: < 5.14.21-150400.15.59.1
- (no CPE)range: < 5.14.21-150500.13.27.2
- (no CPE)range: < 5.14.21-150400.15.59.1
- (no CPE)range: < 5.14.21-150400.15.59.1
- (no CPE)range: < 5.14.21-150400.14.72.1
- (no CPE)range: < 5.14.21-150500.33.23.1
- (no CPE)range: < 5.14.21-150500.55.36.1
- (no CPE)range: < 6.6.1-1.1
- (no CPE)range: < 5.14.21-150400.15.59.1
- (no CPE)range: < 5.14.21-150500.13.27.2
- (no CPE)range: < 5.14.21-150400.14.72.1
- (no CPE)range: < 5.14.21-150500.33.23.1
- (no CPE)range: < 5.14.21-150500.55.36.1
- (no CPE)range: < 5.14.21-150400.15.59.1
- (no CPE)range: < 5.14.21-150500.13.27.1
- (no CPE)range: < 5.14.21-150500.55.36.1
- (no CPE)range: < 5.14.21-150500.55.36.1
- (no CPE)range: < 5.14.21-150400.14.72.1
- (no CPE)range: < 5.14.21-150500.33.23.1
- (no CPE)range: < 5.14.21-150500.55.36.1.150500.6.15.3
- (no CPE)range: < 5.14.21-150500.55.36.1.150500.6.15.3
- (no CPE)range: < 5.14.21-150500.55.36.1
- (no CPE)range: < 5.14.21-150500.55.36.1
- (no CPE)range: < 5.14.21-150500.55.36.1
- (no CPE)range: < 5.14.21-150500.55.36.1
- (no CPE)range: < 5.14.21-150500.55.36.1
- (no CPE)range: < 5.14.21-150500.55.36.1
- (no CPE)range: < 5.14.21-150500.55.36.1
- (no CPE)range: < 1-150400.1.3.1
- (no CPE)range: < 11-150400.2.3
- (no CPE)range: < 9-150500.6.2
- (no CPE)range: < 8-150500.2.2
- (no CPE)range: < 6-150500.2.2
- (no CPE)range: < 1-150500.11.3.2
- (no CPE)range: < 9-150500.6.2
- (no CPE)range: < 8-150500.2.3
- (no CPE)range: < 6-150500.2.3
- (no CPE)range: < 1-150500.11.5.1
- (no CPE)range: < 5.14.21-150500.55.36.1
- (no CPE)range: < 5.14.21-150400.15.59.1
- (no CPE)range: < 5.14.21-150500.13.27.2
- (no CPE)range: < 5.14.21-150400.15.59.1
- (no CPE)range: < 5.14.21-150400.15.59.1
- (no CPE)range: < 5.14.21-150500.13.27.2
- (no CPE)range: < 5.14.21-150400.15.59.1
- (no CPE)range: < 5.14.21-150500.13.27.2
- (no CPE)range: < 5.14.21-150400.14.72.1
- (no CPE)range: < 5.14.21-150500.33.23.1
- (no CPE)range: < 5.14.21-150500.55.36.1
- (no CPE)range: < 5.14.21-150500.55.36.1
- (no CPE)range: < 5.14.21-150400.15.59.1
- (no CPE)range: < 5.14.21-150500.13.27.2
- (no CPE)range: < 5.14.21-150400.14.72.1
- (no CPE)range: < 5.14.21-150500.33.23.1
- (no CPE)range: < 5.14.21-150500.55.36.1
- (no CPE)range: < 5.14.21-150400.15.59.1
- (no CPE)range: < 5.14.21-150500.13.27.1
- (no CPE)range: < 5.14.21-150500.55.36.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- lists.debian.org/debian-lts-announce/2024/01/msg00005.htmlmitremailing-list
- bugzilla.suse.com/show_bug.cgimitre
- cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.5.9mitre
- git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/mitre
- git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/mitre
- git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/mitre
News mentions
0No linked articles in our index yet.