Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-0584

Опубликовано: 23 нояб. 2023
Источник: redhat
CVSS3: 0

Описание

A use-after-free issue was found in igmp_start_timer in net/ipv4/igmp.c in the network sub-component in the Linux Kernel. This flaw allows a local user to observe a refcnt use-after-free issue when receiving an igmp query packet, leading to a kernel information leak.

Отчет

Red Hat Product Security does not consider this to be a vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2258584kernel: refcnt uaf issue when receiving igmp query packet in igmp_start_timer

0 Low

CVSS3

Связанные уязвимости

ubuntu
около 2 лет назад

Rejected reason: Do not use this CVE as it is duplicate of CVE-2023-6932

nvd
около 2 лет назад

Rejected reason: Do not use this CVE as it is duplicate of CVE-2023-6932

msrc
5 месяцев назад

Rejected reason: Do not use this CVE as it is duplicate of CVE-2023-6932

CVSS3: 6.3
github
около 2 лет назад

A use-after-free issue was found in igmp_start_timer in net/ipv4/igmp.c in the network sub-component in the Linux Kernel. This flaw allows a local user to observe a refcnt use-after-free issue when receiving an igmp query packet, leading to a kernel information leak.

CVSS3: 5.5
fstec
около 2 лет назад

Уязвимость реализации протокола IGMPv2 ядра операционной системы Linux , позволяющая нарушителю получить доступ к защищаемой информации

0 Low

CVSS3