Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2023-6121
HistoryNov 16, 2023 - 3:15 p.m.

CVE-2023-6121

2023-11-1615:15:11
Debian Security Bug Tracker
security-tracker.debian.org
17
cve-2023-6121
remote attacker
tcp packet
heap-based buffer overflow
kmalloc data
kernel ring buffer
dmesg
unix

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

4.7 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

67.8%

An out-of-bounds read vulnerability was found in the NVMe-oF/TCP subsystem in the Linux kernel. This issue may allow a remote attacker to send a crafted TCP packet, triggering a heap-based buffer overflow that results in kmalloc data being printed and potentially leaked to the kernel ring buffer (dmesg).

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

4.7 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

67.8%