Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-12914

Опубликовано: 17 окт. 2023
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2023-12914: Unbreakable Enterprise kernel-container security update (IMPORTANT)

[5.4.17-2136.323.8.2.el7]

  • netfilter: nfnetlink_osf: avoid OOB read (Wander Lairson Costa) [Orabug: 35824307]
  • netfilter: xt_sctp: validate the flag_info count (Wander Lairson Costa) [Orabug: 35824307]
  • netfilter: xt_u32: validate user space input (Wander Lairson Costa) [Orabug: 35824307]
  • netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Kyle Zeng) [Orabug: 35824307] {CVE-2023-42753}

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

kernel-uek-container

5.4.17-2136.323.8.2.el7

kernel-uek-container-debug

5.4.17-2136.323.8.2.el7

Связанные CVE

Связанные уязвимости

CVSS3: 7
ubuntu
больше 1 года назад

An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitrarily increment/decrement a memory buffer out-of-bound. This issue may allow a local user to crash the system or potentially escalate their privileges on the system.

CVSS3: 7
redhat
больше 1 года назад

An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitrarily increment/decrement a memory buffer out-of-bound. This issue may allow a local user to crash the system or potentially escalate their privileges on the system.

CVSS3: 7
nvd
больше 1 года назад

An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitrarily increment/decrement a memory buffer out-of-bound. This issue may allow a local user to crash the system or potentially escalate their privileges on the system.

CVSS3: 7.8
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 7
debian
больше 1 года назад

An array indexing vulnerability was found in the netfilter subsystem o ...