Lucene search

K
cve[email protected]CVE-2023-22024
HistorySep 20, 2023 - 9:15 p.m.

CVE-2023-22024

2023-09-2021:15:11
web.nvd.nist.gov
101
cve-2023-22024
unbreakable enterprise kernel
uek
rds module
setsockopt
cap_net_admin
kernel crash
nvd
security vulnerability

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

5.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.9%

In the Unbreakable Enterprise Kernel (UEK), the RDS module in UEK has two setsockopt(2) options, RDS_CONN_RESET and RDS6_CONN_RESET, that are not re-entrant. A malicious local user with CAP_NET_ADMIN can use this to crash the kernel. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

Affected configurations

NVD
Node
oraclevm_serverMatch3.0
OR
oraclelinuxMatch6-
OR
oraclelinuxMatch7-
OR
oraclelinuxMatch8-
OR
oraclelinuxMatch9-

CNA Affected

[
  {
    "product": "Oracle Linux",
    "vendor": "Oracle Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "Oracle Linux: 6"
      },
      {
        "status": "affected",
        "version": "Oracle Linux: 7"
      },
      {
        "status": "affected",
        "version": "Oracle Linux: 8"
      },
      {
        "status": "affected",
        "version": "Oracle Linux: 9"
      }
    ]
  },
  {
    "product": "Oracle VM",
    "vendor": "Oracle Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "Oracle VM: 3"
      }
    ]
  }
]

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

5.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.9%

Related for CVE-2023-22024