5.5
CVE-2023-52702
- EPSS 0.25%
- Veröffentlicht 21.05.2024 16:15:12
- Zuletzt bearbeitet 31.12.2024 20:19:13
- Erkennungen
net: openvswitch: fix possible memory leak in ovs_meter_cmd_set()
In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix possible memory leak in ovs_meter_cmd_set() old_meter needs to be free after it is detached regardless of whether the new meter is successfully attached.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.8 < 5.10.169
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.95
Linux ≫ Linux Kernel Version >= 5.16 < 6.1.13
Linux ≫ Linux Kernel Version 6.2 Update rc1
Linux ≫ Linux Kernel Version 6.2 Update rc2
Linux ≫ Linux Kernel Version 6.2 Update rc3
Linux ≫ Linux Kernel Version 6.2 Update rc4
Linux ≫ Linux Kernel Version 6.2 Update rc5
Linux ≫ Linux Kernel Version 6.2 Update rc6
Linux ≫ Linux Kernel Version 6.2 Update rc7
Linux ≫ Linux Kernel Version 6.2 Update rc8
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.16 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-401 Missing Release of Memory after Effective Lifetime
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
https://git.kernel.org/stable/c/1563e998a938f095548054ef09e277b562b79536
https://git.kernel.org/stable/c/2fa28f5c6fcbfc794340684f36d2581b4f2d20b5
https://git.kernel.org/stable/c/c0f65ee0a3329eb4b94beaef0268633696e2d0c6
https://git.kernel.org/stable/c/e336a9e08618203a456fb5367f1387b14554f55e