PT-2024-13298 · Linux+2 · Linux Kernel+2
Msuhanov
·
Published
2023-09-28
·
Updated
2026-05-26
·
CVE-2023-45896
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.5.11
Linux kernel versions through 6.8.0
Description
The issue allows a physically proximate attacker to read kernel memory by mounting a filesystem and then leveraging local access to trigger an out-of-bounds read. A length value can be larger than the amount of memory allocated. This can occur if a Linux distribution is configured to allow unprivileged mounts of removable media.
Recommendations
For Linux kernel versions prior to 6.5.11, update to version 6.5.11 or later to resolve the issue.
For Linux kernel versions through 6.8.0, consider restricting unprivileged mounts of removable media as a temporary workaround until a patch is available.
Fix
DoS
Improper Access Control
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Os