Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3qhf-qr39-9c9w

Опубликовано: 09 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 3.2

Описание

A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, potentially leading to an information disclosure.

A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, potentially leading to an information disclosure.

EPSS

Процентиль: 1%
0.00009
Низкий

3.2 Low

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 3.2
ubuntu
около 2 лет назад

A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, potentially leading to an information disclosure.

CVSS3: 3.2
redhat
около 2 лет назад

A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, potentially leading to an information disclosure.

CVSS3: 3.2
nvd
около 2 лет назад

A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, potentially leading to an information disclosure.

CVSS3: 4.4
msrc
около 2 лет назад

Kernel: xfrm: out-of-bounds read in __xfrm_state_filter_match()

CVSS3: 3.2
debian
около 2 лет назад

A flaw was found in the XFRM subsystem in the Linux kernel. The specif ...

EPSS

Процентиль: 1%
0.00009
Низкий

3.2 Low

CVSS3

Дефекты

CWE-125