Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-70078
HistorySep 12, 2023 - 12:00 a.m.

Linux kernel out-of-bounds read vulnerability (CNVD-2023-70078)

2023-09-1200:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
linux kernel
out-of-bounds read
vulnerability
xfrma_mtimer_thresh
netlink attributes
sensitive heap data
exploitation

0.0005 Low

EPSS

Percentile

17.6%

Linux kernel is the kernel used by Linux, the open source operating system of the Linux Foundation in the United States. The Linux kernel suffers from an out-of-bounds read vulnerability that can be exploited by an attacker to cause a 4-byte out-of-bounds read of XFRMA_MTIMER_THRESH when parsing netlink attributes, resulting in the leakage of sensitive heap data into user space.