7.8

CVE-2023-35788

Exploit
An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.19 < 4.19.285
Linux ≫ Linux Kernel Version >= 4.20 < 5.4.246
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.183
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.116
Linux ≫ Linux Kernel Version >= 5.16 < 6.1.33
Linux ≫ Linux Kernel Version >= 6.2 < 6.3.7
Debian ≫ Debian Linux Version 12.0
Netapp ≫ H300s Firmware Version -
   Netapp ≫ H300s Version -
Netapp ≫ H500s Firmware Version -
   Netapp ≫ H500s Version -
Netapp ≫ H700s Firmware Version -
   Netapp ≫ H700s Version -
Netapp ≫ H410s Firmware Version -
   Netapp ≫ H410s Version -
Netapp ≫ H410c Firmware Version -
   Netapp ≫ H410c Version -
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 22.04 SwEdition lts
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.406
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADP 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html
Third Party Advisory
Mailing List
https://www.debian.org/security/2023/dsa-5480
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2023/07/msg00030.html
Third Party Advisory
Mailing List
https://www.debian.org/security/2023/dsa-5448
Third Party Advisory
http://packetstormsecurity.com/files/174577/Kernel-Live-Patch-Security-Notice-LSN-0097-1.html
Third Party Advisory
VDB Entry
http://www.openwall.com/lists/oss-security/2023/06/17/1
Exploit
Mailing List
https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.3.7
Patch
Mailing List
https://git.kernel.org/linus/4d56304e5827c8cc8cc18c75343d283af7c4825c
Patch
https://security.netapp.com/advisory/ntap-20230714-0002/
Third Party Advisory
https://www.openwall.com/lists/oss-security/2023/06/07/1
Exploit
Mailing List