Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-0590
HistoryFeb 01, 2023 - 12:00 a.m.

CVE-2023-0590

2023-02-0100:00:00
ubuntu.com
ubuntu.com
22
linux kernel
qdisc_graft
denial of service
race problem
patch eapply未applied

4.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

9.2%

A use-after-free flaw was found in qdisc_graft in net/sched/sch_api.c in
the Linux Kernel due to a race problem. This flaw leads to a denial of
service issue. If patch ebda44da44f6 (“net: sched: fix race condition in
qdisc_graft()”) not applied yet, then kernel could be affected.

OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchlinux< 5.4.0-156.173UNKNOWN
ubuntu22.04noarchlinux< 5.15.0-60.66UNKNOWN
ubuntu22.10noarchlinux< 5.19.0-31.32UNKNOWN
ubuntu20.04noarchlinux-aws< 5.4.0-1107.115UNKNOWN
ubuntu22.04noarchlinux-aws< 5.15.0-1030.34UNKNOWN
ubuntu22.10noarchlinux-aws< 5.19.0-1019.20UNKNOWN
ubuntu20.04noarchlinux-aws-5.15< 5.15.0-1030.34~20.04.1UNKNOWN
ubuntu18.04noarchlinux-aws-5.4< 5.4.0-1107.115~18.04.1UNKNOWN
ubuntu20.04noarchlinux-azure< 5.4.0-1114.120UNKNOWN
ubuntu22.04noarchlinux-azure< 5.15.0-1033.40UNKNOWN
Rows per page:
1-10 of 591

References

4.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

9.2%