Lucene search

K
redhatcveRedhat.comRH:CVE-2023-35001
HistoryJul 10, 2023 - 4:27 p.m.

CVE-2023-35001

2023-07-1016:27:59
redhat.com
access.redhat.com
65
netfilter
linux kernel
oob memory access
local privilege escalation
cap_net_admin
blacklisting
data alignment

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

17.1%

An out-of-bounds (OOB) memory access flaw was found in the Netfilter module in the Linux kernel’s nft_byteorder_eval in net/netfilter/nft_byteorder.c. A bound check failure allows a local attacker with CAP_NET_ADMIN access to cause a local privilege escalation issue due to incorrect data alignment.

Mitigation

To mitigate this issue, it is possible to prevent the affected code from being loaded by blacklisting the kernel netfilter module.

For instructions relating to how to blacklist a kernel module refer to: <https://access.redhat.com/solutions/41278&gt;

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

17.1%