Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w6wh-qr7x-h932

Опубликовано: 02 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large number of actions, while copying and reserving memory for a new action of a new flow, the reserve_sfa_size() function does not return -EMSGSIZE as expected, potentially leading to an out-of-bounds write access. This flaw allows a local user to crash or potentially escalate their privileges on the system.

An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large number of actions, while copying and reserving memory for a new action of a new flow, the reserve_sfa_size() function does not return -EMSGSIZE as expected, potentially leading to an out-of-bounds write access. This flaw allows a local user to crash or potentially escalate their privileges on the system.

EPSS

Процентиль: 72%
0.00758
Низкий

7.8 High

CVSS3

Дефекты

CWE-192
CWE-681
CWE-787

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 3 года назад

An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large number of actions, while copying and reserving memory for a new action of a new flow, the reserve_sfa_size() function does not return -EMSGSIZE as expected, potentially leading to an out-of-bounds write access. This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVSS3: 7.8
redhat
около 3 лет назад

An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large number of actions, while copying and reserving memory for a new action of a new flow, the reserve_sfa_size() function does not return -EMSGSIZE as expected, potentially leading to an out-of-bounds write access. This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVSS3: 7.8
nvd
почти 3 года назад

An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large number of actions, while copying and reserving memory for a new action of a new flow, the reserve_sfa_size() function does not return -EMSGSIZE as expected, potentially leading to an out-of-bounds write access. This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVSS3: 7.8
debian
почти 3 года назад

An integer coercion error was found in the openvswitch kernel module. ...

CVSS3: 7.8
fstec
около 3 лет назад

Уязвимость функции reserve_sfa_size() модуля openvswitch ядра операционной системы Linux, позволяющая нарушителю повысить свои привилегии или вызвать отказ в обслуживании

EPSS

Процентиль: 72%
0.00758
Низкий

7.8 High

CVSS3

Дефекты

CWE-192
CWE-681
CWE-787