Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-35788

Опубликовано: 29 мая 2023
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.

A flaw was found in the TC flower classifier (cls_flower) in the Networking subsystem of the Linux kernel. This issue occurs when sending two TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets with a total size of 252 bytes, which results in an out-of-bounds write when the third packet enters fl_set_geneve_opt, potentially leading to a denial of service or privilege escalation.

Отчет

Red Hat Enterprise Linux 6 is not affected by this flaw as it did not include support for the TC flower classifier.

Меры по смягчению последствий

This flaw can be mitigated by preventing the affected cls_flower kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2023:482129.08.2023
Red Hat Enterprise Linux 7kernelFixedRHSA-2023:481929.08.2023
Red Hat Enterprise Linux 7kpatch-patchFixedRHSA-2023:483429.08.2023
Red Hat Enterprise Linux 7.7 Advanced Update SupportkernelFixedRHSA-2023:469722.08.2023
Red Hat Enterprise Linux 7.7 Telco Extended Update SupportkernelFixedRHSA-2023:469722.08.2023
Red Hat Enterprise Linux 7.7 Update Services for SAP SolutionskernelFixedRHSA-2023:469722.08.2023
Red Hat Enterprise Linux 7.7 Update Services for SAP Solutionskpatch-patchFixedRHSA-2023:469822.08.2023
Red Hat Enterprise Linux 8kernel-rtFixedRHSA-2023:525519.09.2023
Red Hat Enterprise Linux 8kpatch-patchFixedRHSA-2023:522119.09.2023

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2215768kernel: cls_flower: out-of-bounds write in fl_set_geneve_opt()

EPSS

Процентиль: 1%
0.00009
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 2 лет назад

An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.

CVSS3: 7.8
nvd
около 2 лет назад

An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.

CVSS3: 7.8
msrc
почти 2 года назад

Описание отсутствует

CVSS3: 7.8
debian
около 2 лет назад

An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c ...

suse-cvrf
почти 2 года назад

Security update for the Linux Kernel (Live Patch 13 for SLE 15 SP4)

EPSS

Процентиль: 1%
0.00009
Низкий

7.8 High

CVSS3

Уязвимость CVE-2023-35788