Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-3812

Опубликовано: 24 июл. 2023
Источник: debian
EPSS Низкий

Описание

An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed6.0.8-1package
linuxfixed5.10.158-1bullseyepackage
linuxfixed4.19.269-1busterpackage

Примечания

  • https://git.kernel.org/linus/363a5328f4b0517e59572118ccfb7c626d81dca9 (6.1-rc4)

EPSS

Процентиль: 0%
0.00008
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 2 лет назад

An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVSS3: 7.8
redhat
около 3 лет назад

An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVSS3: 7.8
nvd
больше 2 лет назад

An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVSS3: 7.8
msrc
больше 2 лет назад

Kernel: tun: bugs for oversize packet when napi frags enabled in tun_napi_alloc_frags

CVSS3: 7.8
github
больше 2 лет назад

An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system.

EPSS

Процентиль: 0%
0.00008
Низкий