Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7wwm-57j8-wx2j

Опубликовано: 29 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness error, leading to a buffer overflow and remote code execution via HELLO or one of the AUTH frames. This occurs because of an untrusted length taken from a TCP packet in ceph_decode_32.

An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness error, leading to a buffer overflow and remote code execution via HELLO or one of the AUTH frames. This occurs because of an untrusted length taken from a TCP packet in ceph_decode_32.

EPSS

Процентиль: 99%
0.45301
Средний

8.8 High

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 3 года назад

An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness error, leading to a buffer overflow and remote code execution via HELLO or one of the AUTH frames. This occurs because of an untrusted length taken from a TCP packet in ceph_decode_32.

CVSS3: 8.8
redhat
почти 3 года назад

An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness error, leading to a buffer overflow and remote code execution via HELLO or one of the AUTH frames. This occurs because of an untrusted length taken from a TCP packet in ceph_decode_32.

CVSS3: 8.8
nvd
почти 3 года назад

An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness error, leading to a buffer overflow and remote code execution via HELLO or one of the AUTH frames. This occurs because of an untrusted length taken from a TCP packet in ceph_decode_32.

CVSS3: 8.8
msrc
почти 3 года назад

An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness error leading to a buffer overflow and remote code execution via HELLO or one of the AUTH frames. This occurs because of an untrusted length taken from a TCP packet in ceph_decode_32.

CVSS3: 8.8
debian
почти 3 года назад

An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel ...

EPSS

Процентиль: 99%
0.45301
Средний

8.8 High

CVSS3

Дефекты

CWE-120