Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9xgv-7fjq-ccw2

Опубликовано: 01 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket.

A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket.

EPSS

Процентиль: 2%
0.00017
Низкий

7 High

CVSS3

Дефекты

CWE-125
CWE-362

Связанные уязвимости

CVSS3: 7
ubuntu
почти 3 года назад

A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket.

CVSS3: 6.7
redhat
почти 3 года назад

A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket.

CVSS3: 7
nvd
почти 3 года назад

A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket.

CVSS3: 7
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 7
debian
почти 3 года назад

A race condition was found in the Linux kernel's IP framework for tran ...

EPSS

Процентиль: 2%
0.00017
Низкий

7 High

CVSS3

Дефекты

CWE-125
CWE-362