Lucene search

K
redhatcveRedhat.comRH:CVE-2023-1076
HistoryFeb 27, 2023 - 6:30 p.m.

CVE-2023-1076

2023-02-2718:30:24
redhat.com
access.redhat.com
30
linux kernel
tun/tap
local user
network filters
unauthorized access
mitigation
blacklist a kernel module

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

0.0004 Low

EPSS

Percentile

15.7%

A flaw was found in the Linux kernel’s TUN/TAP functionality. This issue could allow a local user to bypass network filters and get unauthorized access to some resources.

Mitigation

To mitigate this issue, prevent modules tap and tun from being loaded. Please see <https://access.redhat.com/solutions/41278&gt; for how to blacklist a kernel module to prevent it from loading automatically.

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

0.0004 Low

EPSS

Percentile

15.7%