Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-1652

Опубликовано: 12 янв. 2023
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A use-after-free flaw was found in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c in the NFS filesystem in the Linux Kernel. This issue could allow a local attacker to crash the system or it may lead to a kernel information leak problem.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernel-rtAffected
Red Hat Enterprise Linux 9kernelFixedRHSA-2023:658307.11.2023
Red Hat Enterprise Linux 9kernelFixedRHSA-2023:658307.11.2023
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionskernelFixedRHSA-2025:1017401.07.2025
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutionskernel-rtFixedRHSA-2025:1019302.07.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2182031Kernel: use-after-free in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c

EPSS

Процентиль: 1%
0.00012
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 2 лет назад

A use-after-free flaw was found in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c in the NFS filesystem in the Linux Kernel. This issue could allow a local attacker to crash the system or it may lead to a kernel information leak problem.

CVSS3: 7.1
nvd
больше 2 лет назад

A use-after-free flaw was found in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c in the NFS filesystem in the Linux Kernel. This issue could allow a local attacker to crash the system or it may lead to a kernel information leak problem.

CVSS3: 7.1
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 7.1
debian
больше 2 лет назад

A use-after-free flaw was found in nfsd4_ssc_setup_dul in fs/nfsd/nfs4 ...

suse-cvrf
больше 2 лет назад

Security update for the Linux Kernel (Live Patch 10 for SLE 15 SP4)

EPSS

Процентиль: 1%
0.00012
Низкий

7.8 High

CVSS3