Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-39190

Опубликовано: 09 окт. 2023
Источник: redhat
CVSS3: 0

Описание

[REJECTED CVE] An array index out-of-bounds write access was found in the Linux kernel in the qfq_update_agg() function, which belongs to the net scheduler QFQ (Quick Fair Queueing Plus). This flaw requires CAP_NET_ADMIN to be exploited and could lead to local privilege escalation.

Отчет

This flaw was found to be a duplicate of CVE-2023-31436. Please see https://access.redhat.com/security/cve/CVE-2023-31436 for information about affected products and security errata.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelUnder investigation
Red Hat Enterprise Linux 7kernelUnder investigation
Red Hat Enterprise Linux 7kernel-rtUnder investigation
Red Hat Enterprise Linux 8kernelUnder investigation
Red Hat Enterprise Linux 8kernel-rtUnder investigation
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2226780kernel: sch_qfq: net scheduler out-of-bounds write in qfq_update_agg()

0 Low

CVSS3

Связанные уязвимости

nvd
больше 2 лет назад

Rejected reason: CVE-2023-39190 was found to be a duplicate of CVE-2023-31436. Please see https://access.redhat.com/security/cve/CVE-2023-31436 for information about affected products and security errata.

0 Low

CVSS3