Lucene search

K
rosalinuxROSA LABROSA-SA-2023-2182
HistoryJul 08, 2023 - 8:22 a.m.

Advisory ROSA-SA-2023-2182

2023-07-0808:22:07
ROSA LAB
abf.rosalinux.ru
11
linux kernel 6.1.38
memory management subsystem
remote attacker
privilege escalation
denial of service
rosa-chrome
fixed vulnerability

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

25.6%

software: kernel-6.1 6.1.38
OS: ROSA-CHROME

package_evr_string: kernel-6.1.1-generic-6.1.38-1.src.rpm

CVE-ID: CVE-2023-3269
BDU-ID: 2023-03584
CVE-Crit: HIGH
CVE-DESC: A vulnerability in the memory management subsystem of the Linux operating system kernel is related to memory usage after memory has been freed. Exploitation of the vulnerability could allow an attacker acting remotely to escalate privileges or cause a denial of service
CVE-STATUS: Fixed
CVE-REV: To close, run command: sudo dnf update kernel-6.1-generic

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

25.6%