Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-2860

Опубликовано: 24 июл. 2023
Источник: debian
EPSS Низкий

Описание

An out-of-bounds read vulnerability was found in the SR-IPv6 implementation in the Linux kernel. The flaw exists within the processing of seg6 attributes. The issue results from the improper validation of user-supplied data, which can result in a read past the end of an allocated buffer. This flaw allows a privileged local user to disclose sensitive information on affected installations of the Linux kernel.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed5.19.11-1package
linuxfixed5.10.148-1bullseyepackage
linuxfixed4.19.260-1busterpackage

Примечания

  • https://www.zerodayinitiative.com/advisories/ZDI-CAN-18511/

  • https://git.kernel.org/linus/84a53580c5d2138c7361c7c3eea5b31827e63b35 (6.0-rc5)

EPSS

Процентиль: 0%
0.00007
Низкий

Связанные уязвимости

CVSS3: 4.4
ubuntu
почти 2 года назад

An out-of-bounds read vulnerability was found in the SR-IPv6 implementation in the Linux kernel. The flaw exists within the processing of seg6 attributes. The issue results from the improper validation of user-supplied data, which can result in a read past the end of an allocated buffer. This flaw allows a privileged local user to disclose sensitive information on affected installations of the Linux kernel.

CVSS3: 4.4
redhat
почти 3 года назад

An out-of-bounds read vulnerability was found in the SR-IPv6 implementation in the Linux kernel. The flaw exists within the processing of seg6 attributes. The issue results from the improper validation of user-supplied data, which can result in a read past the end of an allocated buffer. This flaw allows a privileged local user to disclose sensitive information on affected installations of the Linux kernel.

CVSS3: 4.4
nvd
почти 2 года назад

An out-of-bounds read vulnerability was found in the SR-IPv6 implementation in the Linux kernel. The flaw exists within the processing of seg6 attributes. The issue results from the improper validation of user-supplied data, which can result in a read past the end of an allocated buffer. This flaw allows a privileged local user to disclose sensitive information on affected installations of the Linux kernel.

CVSS3: 4.4
msrc
почти 2 года назад

Описание отсутствует

CVSS3: 4.4
github
почти 2 года назад

An out-of-bounds read vulnerability was found in the SR-IPv6 implementation in the Linux kernel. The flaw exists within the processing of seg6 attributes. The issue results from the improper validation of user-supplied data, which can result in a read past the end of an allocated buffer. This flaw allows a privileged local user to disclose sensitive information on affected installations of the Linux kernel.

EPSS

Процентиль: 0%
0.00007
Низкий