Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3qhf-qr39-9c9w

Опубликовано: 09 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 3.2

Описание

A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, potentially leading to an information disclosure.

A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, potentially leading to an information disclosure.

EPSS

Процентиль: 0%
0.00008
Низкий

3.2 Low

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 3.2
ubuntu
больше 1 года назад

A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, potentially leading to an information disclosure.

CVSS3: 3.2
redhat
больше 1 года назад

A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, potentially leading to an information disclosure.

CVSS3: 3.2
nvd
больше 1 года назад

A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, potentially leading to an information disclosure.

CVSS3: 3.2
debian
больше 1 года назад

A flaw was found in the XFRM subsystem in the Linux kernel. The specif ...

CVSS3: 4.4
fstec
почти 2 года назад

Уязвимость функции xfrm_dump_sa() модуля net/xfrm/xfrm_user.c подсистемы XFRM ядра операционной системы Linux, позволяющая нарушителю получить доступ к защищаемой информации

EPSS

Процентиль: 0%
0.00008
Низкий

3.2 Low

CVSS3

Дефекты

CWE-125