Lucene search

K
zdiLucas Leong (@_wmliang_) of Trend Micro Zero Day InitiativeZDI-23-1491
HistorySep 29, 2023 - 12:00 a.m.

Linux Kernel Netfilter Xtables Out-Of-Bounds Read Information Disclosure Vulnerability

2023-09-2900:00:00
Lucas Leong (@_wmliang_) of Trend Micro Zero Day Initiative
www.zerodayinitiative.com
10
vulnerability
linux kernel
netfilter
xtables
out-of-bounds read
information disclosure
local attackers
sensitive information
high-privileged code
match_flags function
proper validation
user-supplied data
arbitrary code

0.0004 Low

EPSS

Percentile

15.9%

This vulnerability allows local attackers to disclose sensitive information on affected installations of the Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the match_flags function. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the kernel.