Lucene search

K
redhatcveRedhat.comRH:CVE-2023-45898
HistoryOct 23, 2023 - 10:00 p.m.

CVE-2023-45898

2023-10-2322:00:21
redhat.com
access.redhat.com
8
ext4
file system
denial of service
linux kernel
vulnerability
use-after-free
panic

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%

A use-after-free flaw was found in the EXT4 file system, related to ext4_es_insert_extent, in the Linux Kernel. This issue may allow an attacker to create a crafted EXT4 file system which will trigger the vulnerability and lead the kernel to PANIC, causing a denial of service on the targeted system.

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%