Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-39197
HistoryJan 23, 2024 - 12:00 a.m.

CVE-2023-39197

2024-01-2300:00:00
ubuntu.com
ubuntu.com
32
cve-2023-39197
linux kernel
remote user
sensitive information
dccp protocol
bugzilla
rodrigo-zaiden
zdi-can-21202
commit message
conntrack support
unix

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.2

Confidence

High

EPSS

0.002

Percentile

62.5%

An out-of-bounds read vulnerability was found in Netfilter Connection
Tracking (conntrack) in the Linux kernel. This flaw allows a remote user to
disclose sensitive information via the DCCP protocol.

Bugs

Notes

Author Note
rodrigo-zaiden probably also known as ZDI-CAN-21202 commit message has a note that dccp conntrack support might get removed at some point in the future.
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchlinux< 4.15.0-223.235UNKNOWN
ubuntu20.04noarchlinux< 5.4.0-166.183UNKNOWN
ubuntu22.04noarchlinux< 5.15.0-86.96UNKNOWN
ubuntu16.04noarchlinux< 4.4.0-252.286UNKNOWN
ubuntu18.04noarchlinux-aws< 4.15.0-1166.179UNKNOWN
ubuntu20.04noarchlinux-aws< 5.4.0-1113.123UNKNOWN
ubuntu22.04noarchlinux-aws< 5.15.0-1047.52UNKNOWN
ubuntu14.04noarchlinux-aws< 4.4.0-1129.135UNKNOWN
ubuntu16.04noarchlinux-aws< 4.4.0-1167.182UNKNOWN
ubuntu20.04noarchlinux-aws-5.15< 5.15.0-1047.52~20.04.1UNKNOWN
Rows per page:
1-10 of 651

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.2

Confidence

High

EPSS

0.002

Percentile

62.5%