Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-2124

Опубликовано: 12 апр. 2023
Источник: redhat
CVSS3: 7

Описание

An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image after failure (with a dirty log journal). This flaw allows a local user to crash or potentially escalate their privileges on the system.

Отчет

This vulnerability is rated as having a Moderate impact. While theoretically it could lead to privilege escalation, the only known impact is a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelWill not fix
Red Hat Enterprise Linux 7kernel-rtWill not fix
Red Hat Enterprise Linux 8kernel-rtFixedRHSA-2023:454108.08.2023
Red Hat Enterprise Linux 8kernelFixedRHSA-2023:451708.08.2023
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionskernelFixedRHSA-2023:451508.08.2023
Red Hat Enterprise Linux 8.2 Advanced Update SupportkernelFixedRHSA-2023:481529.08.2023
Red Hat Enterprise Linux 8.2 Telecommunications Update Servicekernel-rtFixedRHSA-2023:481729.08.2023
Red Hat Enterprise Linux 8.2 Telecommunications Update ServicekernelFixedRHSA-2023:481529.08.2023
Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionskernelFixedRHSA-2023:481529.08.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2187439kernel: OOB access in the Linux kernel's XFS subsystem

7 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 2 лет назад

An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image after failure (with a dirty log journal). This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVSS3: 7.8
nvd
около 2 лет назад

An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image after failure (with a dirty log journal). This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVSS3: 7.8
debian
около 2 лет назад

An out-of-bounds memory access flaw was found in the Linux kernel\u201 ...

CVSS3: 7.8
fstec
около 2 лет назад

Уязвимость файловой системы XFS ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании или повысить свои привилегии

rocky
больше 1 года назад

Important: kernel security and bug fix update

7 High

CVSS3

Уязвимость CVE-2023-2124