Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-42753

Опубликовано: 22 сент. 2023
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the h->nets array offset, providing attackers with the primitive to arbitrarily increment/decrement a memory buffer out-of-bound. This issue may allow a local user to crash the system or potentially escalate their privileges on the system.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 9kernel-rtAffected
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2024:034723.01.2024
Red Hat Enterprise Linux 7kernelFixedRHSA-2024:034623.01.2024
Red Hat Enterprise Linux 7kpatch-patchFixedRHSA-2024:037123.01.2024
Red Hat Enterprise Linux 7.7 Advanced Update SupportkernelFixedRHSA-2024:099927.02.2024
Red Hat Enterprise Linux 8kernel-rtFixedRHSA-2024:013410.01.2024
Red Hat Enterprise Linux 8kpatch-patchFixedRHSA-2024:008909.01.2024
Red Hat Enterprise Linux 8kernelFixedRHSA-2024:011310.01.2024
Red Hat Enterprise Linux 8.2 Advanced Update SupportkernelFixedRHSA-2024:040325.01.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-191->CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2239843kernel: netfilter: potential slab-out-of-bound access due to integer underflow

EPSS

Процентиль: 1%
0.00014
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
больше 1 года назад

An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitrarily increment/decrement a memory buffer out-of-bound. This issue may allow a local user to crash the system or potentially escalate their privileges on the system.

CVSS3: 7
nvd
больше 1 года назад

An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitrarily increment/decrement a memory buffer out-of-bound. This issue may allow a local user to crash the system or potentially escalate their privileges on the system.

CVSS3: 7.8
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 7
debian
больше 1 года назад

An array indexing vulnerability was found in the netfilter subsystem o ...

CVSS3: 7
github
больше 1 года назад

An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitrarily increment/decrement a memory buffer out-of-bound. This issue may allow a local user to crash the system or potentially escalate their privileges on the system.

EPSS

Процентиль: 1%
0.00014
Низкий

7 High

CVSS3