Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-26545
HistoryFeb 25, 2023 - 12:00 a.m.

CVE-2023-26545

2023-02-2500:00:00
ubuntu.com
ubuntu.com
20
cve-2023-26545
allocation failure
sysctl table
device renaming
unix

CVSS3

4.7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0

Percentile

14.2%

In the Linux kernel before 6.1.13, there is a double free in
net/mpls/af_mpls.c upon an allocation failure (for registering the sysctl
table under a new location) during the renaming of a device.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchlinux< 4.15.0-209.220UNKNOWN
ubuntu20.04noarchlinux< 5.4.0-147.164UNKNOWN
ubuntu22.04noarchlinux< 5.15.0-70.77UNKNOWN
ubuntu22.10noarchlinux< 5.19.0-40.41UNKNOWN
ubuntu16.04noarchlinux< 4.4.0-239.273UNKNOWN
ubuntu18.04noarchlinux-aws< 4.15.0-1154.167UNKNOWN
ubuntu20.04noarchlinux-aws< 5.4.0-1100.108UNKNOWN
ubuntu22.04noarchlinux-aws< 5.15.0-1034.38UNKNOWN
ubuntu22.10noarchlinux-aws< 5.19.0-1023.24UNKNOWN
ubuntu14.04noarchlinux-aws< 4.4.0-1117.123UNKNOWN
Rows per page:
1-10 of 841

References

CVSS3

4.7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0

Percentile

14.2%