Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-3090
HistoryJun 28, 2023 - 12:00 a.m.

CVE-2023-3090

2023-06-2800:00:00
ubuntu.com
ubuntu.com
54
linux kernel
ipvlan
local privilege escalation
vulnerability
local
privilege
escalation

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%

A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network
driver can be exploited to achieve local privilege escalation. The
out-of-bounds write is caused by missing skb->cb initialization in the
ipvlan network driver. The vulnerability is reachable if CONFIG_IPVLAN is
enabled. We recommend upgrading past commit
90cbed5247439a966b645b34eb0a2e037836ea8e.

Rows per page:
1-10 of 861

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%