Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-52429
HistoryFeb 12, 2024 - 12:00 a.m.

CVE-2023-52429

2024-02-1200:00:00
ubuntu.com
ubuntu.com
18
linux kernel
dm_table_create
vulnerability
cve-2023-52429
int_max bytes
missing check

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

5.4

Confidence

High

EPSS

0

Percentile

5.1%

dm_table_create in drivers/md/dm-table.c in the Linux kernel through 6.7.4
can attempt to (in alloc_targets) allocate more than INT_MAX bytes, and
crash, because of a missing check for struct dm_ioctl.target_count.

Bugs

Notes

Author Note
Priority reason: Requires CAP_SYS_ADMIN (aka root) in the initial namespace
cache-use-only Duplicates CVE-2024-23851
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchlinux< 4.15.0-224.236UNKNOWN
ubuntu20.04noarchlinux< 5.4.0-176.196UNKNOWN
ubuntu22.04noarchlinux< 5.15.0-102.112UNKNOWN
ubuntu23.10noarchlinux< 6.5.0-27.28UNKNOWN
ubuntu16.04noarchlinux< 4.4.0-253.287UNKNOWN
ubuntu18.04noarchlinux-aws< 4.15.0-1167.180UNKNOWN
ubuntu20.04noarchlinux-aws< 5.4.0-1122.132UNKNOWN
ubuntu22.04noarchlinux-aws< 5.15.0-1057.63UNKNOWN
ubuntu23.10noarchlinux-aws< 6.5.0-1017.17UNKNOWN
ubuntu14.04noarchlinux-aws< 4.4.0-1130.136UNKNOWN
Rows per page:
1-10 of 831

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

5.4

Confidence

High

EPSS

0

Percentile

5.1%