Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-3772

Опубликовано: 25 июл. 2023
Источник: debian

Описание

A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed6.4.13-1package
linuxfixed5.10.197-1bullseyepackage

Примечания

  • https://lore.kernel.org/netdev/20230721145103.2714073-1-linma@zju.edu.cn/

  • https://www.openwall.com/lists/oss-security/2023/08/10/1

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 2 года назад

A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of service.

CVSS3: 5.5
redhat
почти 2 года назад

A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of service.

CVSS3: 5.5
nvd
почти 2 года назад

A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of service.

CVSS3: 4.4
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 5.5
github
почти 2 года назад

A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of service.