Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-31436

Опубликовано: 13 апр. 2023
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can exceed QFQ_MIN_LMAX.

An out-of-bounds memory access flaw was found in the Linux kernel’s traffic control (QoS) subsystem in how a user triggers the qfq_change_class function with an incorrect MTU value of the network device used as lmax. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Меры по смягчению последствий

To mitigate this issue, prevent the module, sch_qfq from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected
Red Hat Enterprise Linux 6 Extended Lifecycle SupportkernelFixedRHSA-2024:183116.04.2024
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2023:742421.11.2023
Red Hat Enterprise Linux 7kernelFixedRHSA-2023:742321.11.2023
Red Hat Enterprise Linux 7kpatch-patchFixedRHSA-2024:132313.03.2024
Red Hat Enterprise Linux 8kernel-rtFixedRHSA-2023:690114.11.2023
Red Hat Enterprise Linux 8kernelFixedRHSA-2023:707714.11.2023
Red Hat Enterprise Linux 8.2 Advanced Update SupportkernelFixedRHSA-2024:126812.03.2024
Red Hat Enterprise Linux 8.2 Telecommunications Update Servicekernel-rtFixedRHSA-2024:126912.03.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2192671kernel: out-of-bounds write in qfq_change_class function

EPSS

Процентиль: 8%
0.00033
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 2 лет назад

qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can exceed QFQ_MIN_LMAX.

CVSS3: 7.8
nvd
около 2 лет назад

qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can exceed QFQ_MIN_LMAX.

CVSS3: 7.8
msrc
около 2 лет назад

Описание отсутствует

CVSS3: 7.8
debian
около 2 лет назад

qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2 ...

suse-cvrf
почти 2 года назад

Security update for the Linux Kernel (Live Patch 11 for SLE 15 SP4)

EPSS

Процентиль: 8%
0.00033
Низкий

7 High

CVSS3