PT-2023-8122 · Linux+6 · Linux Kernel+6

Publicado

2023-12-12

·

Atualizado

2024-11-21

·

CVE-2023-51782

CVSS v3.1

7.0

Alta

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.8
Description The issue is related to the rose ioctl function in the net/rose/af rose.c module of the Linux kernel, which implements the Amateur Radio X.25 PLP (Rose) protocol. It is caused by a use-after-free error due to a race condition in the rose accept function. This can allow an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Linux kernel versions prior to 6.6.8, update to version 6.6.8 or later to resolve the issue. As a temporary workaround, consider disabling the rose ioctl function until a patch is available. Restrict access to the net/rose/af rose.c module to minimize the risk of exploitation.

Correção

DoS

Race Condition

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2024-14046
ALT-PU-2024-6818
AZL-33344
BDU:2024-00101
CVE-2023-51782
DLA-3710-1
DLA-3711-1
DSA-5593-1
DSA-5594-1
OESA-2024-1067
OESA-2024-1068
OESA-2024-1069
OESA-2024-1085
OESA-2024-1086
OESA-2024-1087
OPENSUSE-SU-2024_0469-1
OPENSUSE-SU-2024_0515-1
SUSE-SU-2024:0463-1
SUSE-SU-2024:0468-1
SUSE-SU-2024:0469-1
SUSE-SU-2024:0474-1
SUSE-SU-2024:0476-1
SUSE-SU-2024:0478-1
SUSE-SU-2024:0483-1
SUSE-SU-2024:0484-1
SUSE-SU-2024:0514-1
SUSE-SU-2024:0515-1
SUSE-SU-2024:0516-1
SUSE-SU-2024:1669-1
USN-6639-1
USN-6646-1
USN-6647-1
USN-6647-2
USN-6680-1
USN-6680-2
USN-6680-3
USN-6681-1
USN-6681-2
USN-6681-3
USN-6681-4
USN-6686-1
USN-6686-2
USN-6686-3
USN-6686-4
USN-6686-5
USN-6705-1
USN-6716-1

Produtos afetados

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu