Lucene search

K
cve[email protected]CVE-2023-34256
HistoryMay 31, 2023 - 8:15 p.m.

CVE-2023-34256

2023-05-3120:15:10
CWE-125
web.nvd.nist.gov
52
cve-2023-34256
linux kernel
out-of-bounds read
crc16
security vulnerability
nvd

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

5.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

An issue was discovered in the Linux kernel before 6.3.3. There is an out-of-bounds read in crc16 in lib/crc16.c when called from fs/ext4/super.c because ext4_group_desc_csum does not properly check an offset. NOTE: this is disputed by third parties because the kernel is not intended to defend against attackers with the stated “When modifying the block device while it is mounted by the filesystem” access.

Affected configurations

NVD
Node
linuxlinux_kernelRange<6.3.3
Node
suselinux_enterpriseMatch12.0sp5
OR
suselinux_enterpriseMatch15.0sp4
OR
suselinux_enterpriseMatch15.0sp5
Node
debiandebian_linuxMatch10.0

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

5.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%