Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-2019

Опубликовано: 13 апр. 2023
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events. This issue results from the improper management of a reference count. This may allow an attacker to create a denial of service condition on the system.

A flaw was found in the Linux kernel's netdevsim device driver within the scheduling of events. This issue results from improper management of a reference count. This flaw allows an attacker to create a denial of service condition on the system.

Отчет

Red Hat Enterprise Linux 6 and 7 are not affected by this flaw as they did not ship the netdevsim device driver. Red Hat Enterprise Linux 8 is not affected as it did not include the upstream commit that introduced this flaw (0ae3eb7 "netdevsim: fib: Perform the route programming in a non-atomic context").

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelWill not fix
Red Hat Enterprise Linux 9kernel-rtWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-911
https://bugzilla.redhat.com/show_bug.cgi?id=2189137kernel: netdevsim: fib: reference count leak on route deletion failure

EPSS

Процентиль: 3%
0.00016
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
ubuntu
почти 3 года назад

A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events. This issue results from the improper management of a reference count. This may allow an attacker to create a denial of service condition on the system.

CVSS3: 4.4
nvd
почти 3 года назад

A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events. This issue results from the improper management of a reference count. This may allow an attacker to create a denial of service condition on the system.

CVSS3: 4.4
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 4.4
debian
почти 3 года назад

A flaw was found in the Linux kernel's netdevsim device driver, within ...

CVSS3: 4.4
github
почти 3 года назад

A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events. This issue results from the improper management of a reference count. This may allow an attacker to create a denial of service condition on the system.

EPSS

Процентиль: 3%
0.00016
Низкий

5.3 Medium

CVSS3