Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-42755
HistoryOct 05, 2023 - 12:00 a.m.

CVE-2023-42755

2023-10-0500:00:00
ubuntu.com
ubuntu.com
13
cve-2023-42755
ipv4 resource reservation protocol
linux kernel
out-of-bounds read
rsvp classifier
local user
denial of service

CVSS3

6.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

EPSS

0.001

Percentile

21.8%

A flaw was found in the IPv4 Resource Reservation Protocol (RSVP)
classifier in the Linux kernel. The xprt pointer may go beyond the linear
part of the skb, leading to an out-of-bounds read in the rsvp_classify
function. This issue may allow a local user to crash the system and cause a
denial of service.

Bugs

Notes

Author Note
Priority reason: By using unprivileged user namespaces, this can be exploited to achieve local denial of service or data leak.
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchlinux< 4.15.0-219.230UNKNOWN
ubuntu20.04noarchlinux< 5.4.0-165.182UNKNOWN
ubuntu22.04noarchlinux< 5.15.0-87.97UNKNOWN
ubuntu23.04noarchlinux< 6.2.0-35.35UNKNOWN
ubuntu14.04noarchlinux< 3.13.0-194.245UNKNOWN
ubuntu16.04noarchlinux< 4.4.0-246.280UNKNOWN
ubuntu18.04noarchlinux-aws< 4.15.0-1162.175UNKNOWN
ubuntu20.04noarchlinux-aws< 5.4.0-1112.121UNKNOWN
ubuntu22.04noarchlinux-aws< 5.15.0-1048.53UNKNOWN
ubuntu23.04noarchlinux-aws< 6.2.0-1014.14UNKNOWN
Rows per page:
1-10 of 831

References

CVSS3

6.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

EPSS

0.001

Percentile

21.8%