Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-39194
HistoryOct 09, 2023 - 12:00 a.m.

CVE-2023-39194

2023-10-0900:00:00
ubuntu.com
ubuntu.com
11
linux kernel
xfrm subsystem
out-of-bounds read
information disclosure

4.4 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

4.2 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

16.2%

A flaw was found in the XFRM subsystem in the Linux kernel. The specific
flaw exists within the processing of state filters, which can result in a
read past the end of an allocated buffer. This flaw allows a local
privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read,
potentially leading to an information disclosure.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchlinux< 4.15.0-220.231UNKNOWN
ubuntu20.04noarchlinux< 5.4.0-169.187UNKNOWN
ubuntu22.04noarchlinux< 5.15.0-91.101UNKNOWN
ubuntu23.04noarchlinux< 6.2.0-39.40UNKNOWN
ubuntu16.04noarchlinux< 4.4.0-248.282UNKNOWN
ubuntu18.04noarchlinux-aws< 4.15.0-1163.176UNKNOWN
ubuntu20.04noarchlinux-aws< 5.4.0-1116.126UNKNOWN
ubuntu22.04noarchlinux-aws< 5.15.0-1051.56UNKNOWN
ubuntu23.04noarchlinux-aws< 6.2.0-1017.17UNKNOWN
ubuntu14.04noarchlinux-aws< 4.4.0-1125.131UNKNOWN
Rows per page:
1-10 of 791

References

4.4 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

4.2 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

16.2%