Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7889-v87r-4q9r

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.4

Описание

The Linux kernel 4.14.67 mishandles certain interaction among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets, which allows local users to cause a denial of service (memory consumption and system hang) by leveraging root access to execute crafted applications, as demonstrated on CentOS 7.

The Linux kernel 4.14.67 mishandles certain interaction among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets, which allows local users to cause a denial of service (memory consumption and system hang) by leveraging root access to execute crafted applications, as demonstrated on CentOS 7.

EPSS

Процентиль: 32%
0.00122
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 4.4
ubuntu
больше 7 лет назад

The Linux kernel 4.14.67 mishandles certain interaction among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets, which allows local users to cause a denial of service (memory consumption and system hang) by leveraging root access to execute crafted applications, as demonstrated on CentOS 7.

CVSS3: 4.9
redhat
больше 7 лет назад

The Linux kernel 4.14.67 mishandles certain interaction among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets, which allows local users to cause a denial of service (memory consumption and system hang) by leveraging root access to execute crafted applications, as demonstrated on CentOS 7.

CVSS3: 4.4
nvd
больше 7 лет назад

The Linux kernel 4.14.67 mishandles certain interaction among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets, which allows local users to cause a denial of service (memory consumption and system hang) by leveraging root access to execute crafted applications, as demonstrated on CentOS 7.

CVSS3: 4.4
debian
больше 7 лет назад

The Linux kernel 4.14.67 mishandles certain interaction among XFRM Net ...

CVSS3: 4.4
fstec
больше 7 лет назад

Уязвимость ядра операционной системы Linux, связанная с некорректной обработкой определенного взаимодействия между сообщениями XFRM Netlink, пакетами IPPROTO_AH и пакетами IPPROTO_IP, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 32%
0.00122
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-400