Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-6121

Опубликовано: 06 нояб. 2023
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

An out-of-bounds read vulnerability was found in the NVMe-oF/TCP subsystem in the Linux kernel. This issue may allow a remote attacker to send a crafted TCP packet, triggering a heap-based buffer overflow that results in kmalloc data being printed and potentially leaked to the kernel ring buffer (dmesg).

Меры по смягчению последствий

This flaw can be mitigated by explicitly setting the kernel parameter to restrict unprivileged users from using dmesg:

sudo sysctl -w kernel.dmesg_restrict=1

To make it persistent between system reboots:

echo 'kernel.dmesg_restrict=1' | sudo tee -a /etc/sysctl.conf

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelOut of support scope
Red Hat Enterprise Linux 7kernel-rtOut of support scope
Red Hat Enterprise Linux 9kernel-rtAffected
Red Hat Enterprise Linux 8kernel-rtFixedRHSA-2024:295022.05.2024
Red Hat Enterprise Linux 8kernelFixedRHSA-2024:313822.05.2024
Red Hat Enterprise Linux 9kernelFixedRHSA-2024:239430.04.2024
Red Hat Enterprise Linux 9kernelFixedRHSA-2024:239430.04.2024

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2250043kernel: NVMe: info leak due to out-of-bounds read in nvmet_ctrl_find_get

EPSS

Процентиль: 49%
0.00257
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 1 года назад

An out-of-bounds read vulnerability was found in the NVMe-oF/TCP subsystem in the Linux kernel. This issue may allow a remote attacker to send a crafted TCP packet, triggering a heap-based buffer overflow that results in kmalloc data being printed and potentially leaked to the kernel ring buffer (dmesg).

CVSS3: 4.3
nvd
больше 1 года назад

An out-of-bounds read vulnerability was found in the NVMe-oF/TCP subsystem in the Linux kernel. This issue may allow a remote attacker to send a crafted TCP packet, triggering a heap-based buffer overflow that results in kmalloc data being printed and potentially leaked to the kernel ring buffer (dmesg).

CVSS3: 4.3
msrc
6 месяцев назад

Описание отсутствует

CVSS3: 4.3
debian
больше 1 года назад

An out-of-bounds read vulnerability was found in the NVMe-oF/TCP subsy ...

CVSS3: 4.3
github
больше 1 года назад

An out-of-bounds read vulnerability was found in the NVMe-oF/TCP subsystem in the Linux kernel. This flaw allows a remote attacker to send a crafted TCP packet, triggering a heap-based buffer overflow that results in kmalloc data to be printed (and potentially leaked) to the kernel ring buffer (dmesg).

EPSS

Процентиль: 49%
0.00257
Низкий

4.3 Medium

CVSS3

Уязвимость CVE-2023-6121