Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2j83-334m-g9w4

Опубликовано: 21 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. An unprivileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unrelated kernel memory, causing random kernel crashes and memory corruption.

A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. An unprivileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unrelated kernel memory, causing random kernel crashes and memory corruption.

EPSS

Процентиль: 2%
0.00015
Низкий

7 High

CVSS3

Дефекты

CWE-119
CWE-120

Связанные уязвимости

CVSS3: 6.7
ubuntu
около 2 лет назад

A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. Only privileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unrelated kernel memory, causing random kernel crashes and memory corruption.

CVSS3: 6.7
redhat
больше 2 лет назад

A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. Only privileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unrelated kernel memory, causing random kernel crashes and memory corruption.

CVSS3: 6.7
nvd
около 2 лет назад

A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. Only privileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unrelated kernel memory, causing random kernel crashes and memory corruption.

CVSS3: 6.7
debian
около 2 лет назад

A buffer overflow vulnerability was found in the NVM Express (NVMe) dr ...

CVSS3: 7.8
fstec
около 2 лет назад

Уязвимость функции nvme_add_user_metadata() модуля drivers/nvme/host/ioctl.c драйвера NVMe ядра операционной системы Linux, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 2%
0.00015
Низкий

7 High

CVSS3

Дефекты

CWE-119
CWE-120