Lucene search

K
rosalinuxROSA LABROSA-SA-2023-2113
HistoryFeb 14, 2023 - 1:01 p.m.

Advisory ROSA-SA-2023-2113

2023-02-1413:01:31
ROSA LAB
abf.rosalinux.ru
23
security advisory
kernel 3.10.0-1160.83.1.el7
rosa-sa-2023-2113
netfilter component
stack buffer overflow
nftables
unauthorized access
privilege escalation
cve-2023-0179
bdu-id
critical vulnerability
fixed
update command

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%

Software: kernel 3.10.0-1160.83.1.el7
OS: rosa-server79

package_evr_string: kernel-3.10.0-1160.83.1.el7

CVE-ID: CVE-2023-0179
BDU-ID: 2023-00383
CVE-Crit: HIGH
CVE-DESC: A vulnerability in the netfilter component of the Linux operating system kernel is related to a stack buffer overflow in nftables.
Exploitation of the vulnerability could allow an attacker to gain unauthorized access to protected information and escalate their privileges.
CVE-STATUS: Fixed
CVE-REC: To close, run the yum update command

OSVersionArchitecturePackageVersionFilename
rosaanynoarchkernel< 3.10.0UNKNOWN

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%