Описание
do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race condition (with a resultant use-after-free or NULL pointer dereference).
A use-after-free flaw was found in the do_tls_getsockopt function in net/tls/tls_main.c in the Transport Layer Security (TLS) in the Network subcompact in the Linux kernel. This flaw allows an attacker to cause a NULL pointer dereference problem due to a race condition.
Меры по смягчению последствий
This flaw can be mitigated by preventing the affected Transport Layer Security (TLS) kernel module from loading during the boot time. Ensure the module is added into the blacklist file.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | kernel | Not affected | ||
Red Hat Enterprise Linux 7 | kernel | Not affected | ||
Red Hat Enterprise Linux 7 | kernel-rt | Not affected | ||
Red Hat Enterprise Linux 8 | kernel-rt | Fixed | RHSA-2023:3819 | 27.06.2023 |
Red Hat Enterprise Linux 8 | kernel | Fixed | RHSA-2023:3847 | 27.06.2023 |
Red Hat Enterprise Linux 8.6 Extended Update Support | kernel | Fixed | RHSA-2023:4789 | 29.08.2023 |
Red Hat Enterprise Linux 9 | kernel | Fixed | RHSA-2023:3723 | 21.06.2023 |
Red Hat Enterprise Linux 9 | kernel-rt | Fixed | RHSA-2023:3708 | 21.06.2023 |
Red Hat Enterprise Linux 9 | kernel | Fixed | RHSA-2023:3723 | 21.06.2023 |
Red Hat Enterprise Linux 9.0 Extended Update Support | kernel | Fixed | RHSA-2023:4801 | 29.08.2023 |
Показывать по
Дополнительная информация
Статус:
EPSS
7 High
CVSS3
Связанные уязвимости
do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race condition (with a resultant use-after-free or NULL pointer dereference).
do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race condition (with a resultant use-after-free or NULL pointer dereference).
do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6. ...
EPSS
7 High
CVSS3