Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-0565

Опубликовано: 15 янв. 2024
Источник: nvd
CVSS3: 6.8
CVSS3: 7.4
EPSS Низкий

Описание

An out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-component in the Linux Kernel. This issue occurs due to integer underflow on the memcpy length, leading to a denial of service.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Версия от 6.1.36 (включая) до 6.7 (исключая)
cpe:2.3:o:linux:linux_kernel:6.7:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.7:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.7:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.7:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.7:rc5:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:netapp:ontap_tools:-:*:*:*:*:vmware_vsphere:*:*

EPSS

Процентиль: 22%
0.00073
Низкий

6.8 Medium

CVSS3

7.4 High

CVSS3

Дефекты

CWE-191
CWE-191

Связанные уязвимости

CVSS3: 6.8
ubuntu
почти 2 года назад

An out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-component in the Linux Kernel. This issue occurs due to integer underflow on the memcpy length, leading to a denial of service.

CVSS3: 6.8
redhat
почти 2 года назад

An out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-component in the Linux Kernel. This issue occurs due to integer underflow on the memcpy length, leading to a denial of service.

CVSS3: 7.4
msrc
больше 1 года назад

Kernel: cifs filesystem decryption improper input validation remote code execution vulnerability in function receive_encrypted_standard of client

CVSS3: 6.8
debian
почти 2 года назад

An out-of-bounds memory read flaw was found in receive_encrypted_stand ...

CVSS3: 7.1
github
почти 2 года назад

An out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-component in the Linux Kernel. This issue occurs due to integer underflow on the memcpy length, leading to a denial of service.

EPSS

Процентиль: 22%
0.00073
Низкий

6.8 Medium

CVSS3

7.4 High

CVSS3

Дефекты

CWE-191
CWE-191