CVE-2023-5717 is a moderate-severity out-of-bounds write flaw in the Linux kernel Performance Events (perf_events) subsystem. A low-privileged local attacker could trigger it by reading an inherited performance-event group whose sibling_list is smaller than its child group's list, causing writes outside the intended buffer. Successful exploitation could crash the system, execute code, or elevate privileges; the vulnerability carries a CVSS v3.1 score of 7.8.
The upstream fix adds a group_generation counter to track performance-event group membership changes, propagates that state to inherited groups, and rejects reads with -ECHILD when parent and child generation values or sibling counts differ. Red Hat released corrected kernel packages for affected Red Hat Enterprise Linux 8 and 9 systems and Red Hat Virtualization 4 for RHEL 8. Red Hat noted that the default kernel.perf_event_paranoid=2 setting prevents the vulnerable code path from being triggered.

Get the actors, campaigns, and ATT&CK mapping behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat released fixes for the standard RHEL 8 kernel and RHEL 8 kernel-rt packages through RHSA-2024:0897 and RHSA-2024:0881.
Red Hat issued RHSA-2024:0724 to fix the vulnerability in the RHEL 8.6 Extended Update Support kernel and Red Hat Virtualization 4 for RHEL 8.
Red Hat remediated CVE-2023-5717 in the RHEL 8.8 Extended Update Support kernel through RHSA-2024:0575.
Red Hat issued fixes for the RHEL 9.2 Extended Update Support kernel and kernel-rt packages through RHSA-2024:0448 and RHSA-2024:0439.
The upstream Linux kernel added generation and sibling-count consistency checks for inherited performance-event group reads, rejecting mismatched parent and child groups with -ECHILD. The patch addresses the race underlying CVE-2023-5717.
Red Hat issued RHSA-2024:1306 to fix CVE-2023-5717 in the RHEL 9.0 Extended Update Support kernel-rt package.
Red Hat remediated the vulnerability in the RHEL 9 kernel and RHEL 9.0 Extended Update Support kernel through RHSA-2024:1248 and RHSA-2024:1250.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.