Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-39192
HistoryOct 09, 2023 - 12:00 a.m.

CVE-2023-39192

2023-10-0900:00:00
ubuntu.com
ubuntu.com
16
linux kernel
netfilter subsystem
local attacker
out-of-bounds read
information disclosure

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

5.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.9%

A flaw was found in the Netfilter subsystem in the Linux kernel. The xt_u32
module did not validate the fields in the xt_u32 structure. This flaw
allows a local privileged attacker to trigger an out-of-bounds read by
setting the size fields with a value beyond the array boundaries, leading
to a crash or information disclosure.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchlinux< 4.15.0-220.231UNKNOWN
ubuntu20.04noarchlinux< 5.4.0-169.187UNKNOWN
ubuntu22.04noarchlinux< 5.15.0-91.101UNKNOWN
ubuntu23.04noarchlinux< 6.2.0-39.40UNKNOWN
ubuntu16.04noarchlinux< 4.4.0-248.282UNKNOWN
ubuntu18.04noarchlinux-aws< 4.15.0-1163.176UNKNOWN
ubuntu20.04noarchlinux-aws< 5.4.0-1116.126UNKNOWN
ubuntu22.04noarchlinux-aws< 5.15.0-1051.56UNKNOWN
ubuntu23.04noarchlinux-aws< 6.2.0-1017.17UNKNOWN
ubuntu14.04noarchlinux-aws< 4.4.0-1125.131UNKNOWN
Rows per page:
1-10 of 811

References

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

5.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.9%