Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-4569

Опубликовано: 12 авг. 2023
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A memory leak flaw was found in nft_set_catchall_flush in net/netfilter/nf_tables_api.c in the Linux Kernel. This issue may allow a local attacker to cause double-deactivations of catchall elements, which can result in a memory leak.

Отчет

After engineering's review, it has been concluded that, this CVE do not impact any shipped RHEL Kernel.

Меры по смягчению последствий

Mitigation for this issue is to skip loading the affected module "nftables" onto the system until we have a fix available. This can be done by a blacklist mechanism that will ensure the driver is not loaded at boot time.

How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-402
https://bugzilla.redhat.com/show_bug.cgi?id=2235470kernel: information leak in nft_set_catchall_flush in net/netfilter/nf_tables_api.c

EPSS

Процентиль: 0%
0.00008
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 2 года назад

A memory leak flaw was found in nft_set_catchall_flush in net/netfilter/nf_tables_api.c in the Linux Kernel. This issue may allow a local attacker to cause double-deactivations of catchall elements, which can result in a memory leak.

CVSS3: 5.5
nvd
почти 2 года назад

A memory leak flaw was found in nft_set_catchall_flush in net/netfilter/nf_tables_api.c in the Linux Kernel. This issue may allow a local attacker to cause double-deactivations of catchall elements, which can result in a memory leak.

CVSS3: 5.5
msrc
почти 2 года назад

Описание отсутствует

CVSS3: 5.5
debian
почти 2 года назад

A memory leak flaw was found in nft_set_catchall_flush in net/netfilte ...

CVSS3: 5.5
github
почти 2 года назад

A memory leak flaw was found in nft_set_catchall_flush in net/netfilter/nf_tables_api.c in the Linux Kernel. This issue may allow a local attacker to cause a double-deactivations of catchall elements, which results in a memory leak.

EPSS

Процентиль: 0%
0.00008
Низкий

5.5 Medium

CVSS3