PT-2023-4967 · Linux+3 · Linux Kernel+3

Published

2023-09-06

·

Updated

2024-09-30

·

CVE-2023-4881

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A stack-based out-of-bounds write flaw was found in the netfilter subsystem of the Linux kernel. The nft exthdr eval family of functions writes 4 NULL bytes past the end of the regs argument when the expression length is a multiple of 4 (register size), leading to stack corruption and potential information disclosure or a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-05505
CVE-2023-4881
LSN-0099-1
OESA-2023-1666
OESA-2023-1667
OESA-2023-1668
OESA-2023-1669
OESA-2023-1670
OPENSUSE-SU-2023_3988-1
OPENSUSE-SU-2023_4057-1
OPENSUSE-SU-2023_4058-1
OPENSUSE-SU-2023_4071-1
OPENSUSE-SU-2023_4072-1
OPENSUSE-SU-2023_4072-2
OPENSUSE-SU-2023_4347-1
OPENSUSE-SU-2024:13245-1
OPENSUSE-SU-2024:13704-1
OPENSUSE-SU-2024_1322-1
OPENSUSE-SU-2024_1322-2
OPENSUSE-SU-2024_1332-1
OPENSUSE-SU-2024_1332-2
OPENSUSE-SU-2024_1466-1
OPENSUSE-SU-2024_1480-1
OPENSUSE-SU-2024_1490-1
OPENSUSE-SU-2024_1641-1
SUSE-SU-2023:3988-1
SUSE-SU-2023:4030-1
SUSE-SU-2023:4031-1
SUSE-SU-2023:4032-1
SUSE-SU-2023:4033-1
SUSE-SU-2023:4057-1
SUSE-SU-2023:4058-1
SUSE-SU-2023:4071-1
SUSE-SU-2023:4072-1
SUSE-SU-2023:4072-2
SUSE-SU-2023:4093-1
SUSE-SU-2023:4095-1
SUSE-SU-2023:4142-1
SUSE-SU-2023:4347-1
SUSE-SU-2024:1466-1
SUSE-SU-2024:1480-1
SUSE-SU-2024:1490-1
SUSE-SU-2024:1641-1
SUSE-SU-2024:1643-1
USN-6439-1
USN-6439-2
USN-6440-1
USN-6440-2
USN-6440-3
USN-6441-1
USN-6441-2
USN-6441-3
USN-6442-1
USN-6443-1
USN-6444-1
USN-6444-2
USN-6445-1
USN-6445-2
USN-6446-1
USN-6446-2
USN-6446-3
USN-6454-1
USN-6454-2
USN-6454-3
USN-6454-4
USN-6466-1
USN-6479-1

Affected Products

Linuxmint
Linux Kernel
Suse
Ubuntu