Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-4004

Опубликовано: 19 июл. 2023
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove function with the element, without a NFT_SET_EXT_KEY_END. This issue could allow a local user to crash the system or potentially escalate their privileges on the system.

Меры по смягчению последствий

This flaw can be mitigated by preventing the affected netfilter kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernel-rtFixedRHSA-2023:525519.09.2023
Red Hat Enterprise Linux 8kpatch-patchFixedRHSA-2023:522119.09.2023
Red Hat Enterprise Linux 8kernelFixedRHSA-2023:524419.09.2023
Red Hat Enterprise Linux 8.2 Advanced Update SupportkernelFixedRHSA-2023:743421.11.2023
Red Hat Enterprise Linux 8.2 Telecommunications Update Servicekernel-rtFixedRHSA-2023:743121.11.2023
Red Hat Enterprise Linux 8.2 Telecommunications Update ServicekernelFixedRHSA-2023:743421.11.2023
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutionskpatch-patchFixedRHSA-2023:741721.11.2023

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2225275kernel: netfilter: use-after-free due to improper element removal in nft_pipapo_remove()

EPSS

Процентиль: 2%
0.00015
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 2 года назад

A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove function with the element, without a NFT_SET_EXT_KEY_END. This issue could allow a local user to crash the system or potentially escalate their privileges on the system.

CVSS3: 7.8
nvd
почти 2 года назад

A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove function with the element, without a NFT_SET_EXT_KEY_END. This issue could allow a local user to crash the system or potentially escalate their privileges on the system.

CVSS3: 7.8
msrc
почти 2 года назад

Описание отсутствует

CVSS3: 7.8
debian
почти 2 года назад

A use-after-free flaw was found in the Linux kernel's netfilter in the ...

CVSS3: 7.8
github
почти 2 года назад

A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove function with the element, without a NFT_SET_EXT_KEY_END. This issue could allow a local user to crash the system or potentially escalate their privileges on the system.

EPSS

Процентиль: 2%
0.00015
Низкий

7.8 High

CVSS3