[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2023-4004Date: (C)2023-08-01   (M)2024-04-30


A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove function with the element, without a NFT_SET_EXT_KEY_END. This issue could allow a local user to crash the system or potentially escalate their privileges on the system.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.8CVSS Score :
Exploit Score: 1.8Exploit Score:
Impact Score: 5.9Impact Score:
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector:
Attack Complexity: LOWAccess Complexity:
Privileges Required: LOWAuthentication:
User Interaction: NONEConfidentiality:
Scope: UNCHANGEDIntegrity:
Confidentiality: HIGHAvailability:
Integrity: HIGH 
Availability: HIGH 
  
Reference:
RHSA-2023:7382
RHSA-2023:7389
RHSA-2023:7411
RHSA-2023:7417
RHSA-2023:7431
RHSA-2023:7434
http://packetstormsecurity.com/files/175072/Kernel-Live-Patch-Security-Notice-LSN-0098-1.html
http://packetstormsecurity.com/files/175963/Kernel-Live-Patch-Security-Notice-LSN-0099-1.html
https://access.redhat.com/errata/RHSA-2023:4961
https://access.redhat.com/errata/RHSA-2023:4962
https://access.redhat.com/errata/RHSA-2023:4967
https://access.redhat.com/errata/RHSA-2023:5069
https://access.redhat.com/errata/RHSA-2023:5091
https://access.redhat.com/errata/RHSA-2023:5093
https://access.redhat.com/errata/RHSA-2023:5221
https://access.redhat.com/errata/RHSA-2023:5244
https://access.redhat.com/errata/RHSA-2023:5255
https://access.redhat.com/errata/RHSA-2023:5548
https://access.redhat.com/errata/RHSA-2023:5627
https://access.redhat.com/security/cve/CVE-2023-4004
https://bugzilla.redhat.com/show_bug.cgi?id=2225275
https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html
https://patchwork.ozlabs.org/project/netfilter-devel/patch/20230719190824.21196-1-fw@strlen.de/
https://security.netapp.com/advisory/ntap-20231027-0001/
https://www.debian.org/security/2023/dsa-5480
https://www.debian.org/security/2023/dsa-5492

CWE    1
CWE-416
OVAL    47
oval:org.secpod.oval:def:95061
oval:org.secpod.oval:def:3302250
oval:org.secpod.oval:def:708535
oval:org.secpod.oval:def:4501481
...

© SecPod Technologies