Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m7p8-8c8g-qwrv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls.

In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls.

EPSS

Процентиль: 11%
0.00039
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-119
CWE-787

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 5 лет назад

In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls.

CVSS3: 5.3
redhat
около 5 лет назад

In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls.

CVSS3: 5.3
nvd
около 5 лет назад

In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls.

CVSS3: 5.3
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 5.3
debian
около 5 лет назад

In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net. ...

EPSS

Процентиль: 11%
0.00039
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-119
CWE-787