Lucene search

K
vulnrichmentRedhatVULNRICHMENT:CVE-2023-5685
HistoryMar 22, 2024 - 6:24 p.m.

CVE-2023-5685 Xnio: stackoverflowexception when the chain of notifier states becomes problematically big

2024-03-2218:24:42
CWE-400
redhat
github.com
7
xnio
stackoverflowexception
large notifier states
resource management
denial of service
dos

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.5

Confidence

High

EPSS

0

Percentile

10.3%

SSVC

Exploitation

none

Automatable

yes

Technical Impact

partial

A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier states becomes problematically large can lead to uncontrolled resource management and a possible denial of service (DoS).

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.5

Confidence

High

EPSS

0

Percentile

10.3%

SSVC

Exploitation

none

Automatable

yes

Technical Impact

partial