Lucene search

K
redhatcveRedhat.comRH:CVE-2023-51781
HistoryJan 10, 2024 - 1:35 p.m.

CVE-2023-51781

2024-01-1013:35:57
redhat.com
access.redhat.com
10
linux kernel
atalk_ioctl
use-after-free
unauthorized access
privilege escalation
system crash

7 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

6.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

A use-after-free flaw was found in the Linux kernel’s atalk_ioctl in net/appletalk/ddp.c, due to a race condition in atalk_recvmsg. This flaw allows an attacker to possibly gain unauthorized access, escalate privileges, or cause the system to crash.

Mitigation

No mitigation is currently available for this flaw.

7 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

6.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%