Security readout for executives and security teams
Plain-English summary
CVE-2023-22998 is a Linux kernel denial-of-service flaw in the virtio GPU driver. A local user could trigger a kernel error path that may cause high availability impact. It is not described as remotely exploitable and CISA KEV does not list active exploitation.
Executive priority
Treat as a moderate availability issue. Patch through normal kernel maintenance, faster on shared systems, VDI, CI, or virtualized environments with untrusted local users.
Technical view
Before Linux 6.0.3, virtgpu_object.c misread drm_gem_shmem_get_sg_table failures as NULL instead of error pointers. The CVSS vector is local, low complexity, low privilege, no user interaction, with high availability impact and no stated confidentiality or integrity impact.
Likely exposure
Exposure is most likely on Linux systems running kernels before 6.0.3 where the virtio GPU DRM driver path is present or reachable. Validate distribution backports because package version strings may not match upstream kernel versions.
Exploitation context
The provided sources support local low-privilege denial of service risk. They do not claim remote exploitation, privilege escalation, public exploit availability, or active exploitation in the wild.
Researcher notes
Evidence is limited to the CVE text, upstream commit, Linux 6.0.3 changelog, and Debian LTS advisory. The sources identify the bug class and fix location but do not provide exploit details or broad product-specific impact.
Mitigation direction
- Upgrade to a vendor kernel containing the upstream Linux 6.0.3 fix.
- Apply Debian DLA 3404-1 where affected Debian LTS linux-5.10 packages are used.
- Check Linux distribution advisories for backported fixes and supported package versions.
- Prioritize systems with untrusted local users or exposed virtual graphics workloads.
Validation and detection
- Inventory Linux kernel versions and distribution security patch levels.
- Check whether virtio GPU DRM components are present on relevant systems.
- Confirm the upstream fix commit or vendor backport is included.
- Review logs for unexplained local kernel crashes or GPU driver faults.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-436: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2023-22998 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 5.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H1.83.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
5.5MediumVector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/torvalds/linux/commit/c24968734abfed81c8f93dc5f44a7b7a9aecadfaCVE reference
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.0.3CVE reference
- [debian-lts-announce] 20230502 [SECURITY] [DLA 3404-1] linux-5.10 security updateCVE reference · mailing-list
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Interpretation Conflict
Interpretation Conflict represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
