Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-6238

Опубликовано: 21 нояб. 2023
Источник: nvd
CVSS3: 6.7
EPSS Низкий

Описание

A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. Only privileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unrelated kernel memory, causing random kernel crashes and memory corruption.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*

EPSS

Процентиль: 2%
0.00015
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-120
CWE-120

Связанные уязвимости

CVSS3: 6.7
ubuntu
около 2 лет назад

A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. Only privileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unrelated kernel memory, causing random kernel crashes and memory corruption.

CVSS3: 6.7
redhat
больше 2 лет назад

A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. Only privileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unrelated kernel memory, causing random kernel crashes and memory corruption.

CVSS3: 6.7
debian
около 2 лет назад

A buffer overflow vulnerability was found in the NVM Express (NVMe) dr ...

CVSS3: 7
github
около 2 лет назад

A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. An unprivileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unrelated kernel memory, causing random kernel crashes and memory corruption.

CVSS3: 7.8
fstec
около 2 лет назад

Уязвимость функции nvme_add_user_metadata() модуля drivers/nvme/host/ioctl.c драйвера NVMe ядра операционной системы Linux, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 2%
0.00015
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-120
CWE-120