CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
5.1%
An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image after failure (with a dirty log journal). This flaw allows a local user to crash or potentially escalate their privileges on the system.
Vendor | Product | Version | CPE |
---|---|---|---|
linux | linux_kernel | * | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
debian | debian_linux | 11.0 | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
debian | debian_linux | 12.0 | cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* |
netapp | h300s | - | cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:* |
netapp | h300s_firmware | - | cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:* |
netapp | h410c | - | cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:* |
netapp | h410c_firmware | - | cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:* |
netapp | h410s | - | cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:* |
netapp | h410s_firmware | - | cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:* |
netapp | h500s | - | cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:* |
[
{
"vendor": "n/a",
"product": "Kernel",
"versions": [
{
"version": "Linux kernel 6.4-rc1",
"status": "affected"
}
]
}
]
git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/fs/xfs/xfs_buf_item_recover.c?h=v6.4-rc1&id=22ed903eee23a5b174e240f1cdfa9acf393a5210
lists.debian.org/debian-lts-announce/2023/10/msg00027.html
security.netapp.com/advisory/ntap-20230622-0010/
syzkaller.appspot.com/bug?extid=7e9494b8b399902e994e
www.debian.org/security/2023/dsa-5448
www.debian.org/security/2023/dsa-5480