PT-2023-3470 · Linux+2 · Linux Kernel+2

Publicado

2023-06-07

·

Atualizado

2023-09-04

·

CVE-2023-3117

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a use-after-free flaw in the Netfilter subsystem of the Linux kernel when processing named and anonymous sets in batch requests. This can lead to performing arbitrary reads and writes in kernel memory. A local user with CAP NET ADMIN capability can potentially crash the system or escalate their privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-4368
ALT-PU-2023-4401
ALT-PU-2023-4482
ALT-PU-2023-4663
BDU:2023-03656
CVE-2023-3117
OESA-2023-1435
OESA-2023-1436
OESA-2023-1437
OESA-2023-1438
OESA-2023-1439
OPENSUSE-SU-2023_3171-1
OPENSUSE-SU-2023_3172-1
OPENSUSE-SU-2023_3180-1
OPENSUSE-SU-2023_3182-1
OPENSUSE-SU-2023_3302-1
OPENSUSE-SU-2023_3318-1
OPENSUSE-SU-2023_3391-1
SUSE-SU-2023:3171-1
SUSE-SU-2023:3172-1
SUSE-SU-2023:3180-1
SUSE-SU-2023:3182-1
SUSE-SU-2023:3302-1
SUSE-SU-2023:3318-1
SUSE-SU-2023:3390-1
SUSE-SU-2023:3391-1
SUSE-SU-2023:3421-1
SUSE-SU-2023_3171-1
SUSE-SU-2023_3172-1
SUSE-SU-2023_3180-1
SUSE-SU-2023_3182-1

Produtos afetados

Linux Kernel
Red Os
Suse