Kernel: netfilter: potential slab-out-of-bound access due to integer underflow
CVE-2023-42753
7HIGH
Key Information:
- Vendor
- Red Hat
- Status
- Vendor
- CVE Published:
- 25 September 2023
Summary
An array indexing vulnerability exists in the netfilter subsystem of the Linux kernel due to a missing macro, which can lead to miscalculation of the h->nets
array offset. This flaw enables attackers to exploit memory buffer operations, resulting in potential local system crashes or privilege escalation.
Affected Version(s)
Red Hat Enterprise Linux 7 0:3.10.0-1160.108.1.rt56.1259.el7
Red Hat Enterprise Linux 7 0:3.10.0-1160.108.1.el7
References
CVSS V3.1
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database