Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3qhf-qr39-9c9w

Опубликовано: 09 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 3.2

Описание

A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, potentially leading to an information disclosure.

A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, potentially leading to an information disclosure.

EPSS

Процентиль: 34%
0.00417
Низкий

3.2 Low

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 3.2
ubuntu
почти 3 года назад

A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, potentially leading to an information disclosure.

CVSS3: 3.2
redhat
почти 3 года назад

A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, potentially leading to an information disclosure.

CVSS3: 3.2
nvd
почти 3 года назад

A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, potentially leading to an information disclosure.

CVSS3: 4.4
msrc
почти 3 года назад

Kernel: xfrm: out-of-bounds read in __xfrm_state_filter_match()

CVSS3: 3.2
debian
почти 3 года назад

A flaw was found in the XFRM subsystem in the Linux kernel. The specif ...

EPSS

Процентиль: 34%
0.00417
Низкий

3.2 Low

CVSS3

Дефекты

CWE-125