7.8

CVE-2023-5972

Kernel: the nfta_inner_num and nfta_expr_name netlink attributes accessed without checking its presence in nft_inner.c

A null pointer dereference flaw was found in the nft_inner.c functionality of netfilter in the Linux kernel. This issue could allow a local user to crash the system or escalate their privileges on the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 6.2.1 <= 6.5.10
Linux ≫ Linux Kernel Version 6.2 Update rc1
Linux ≫ Linux Kernel Version 6.2 Update rc2
Linux ≫ Linux Kernel Version 6.2 Update rc3
Linux ≫ Linux Kernel Version 6.2 Update rc4
Linux ≫ Linux Kernel Version 6.2 Update rc5
Linux ≫ Linux Kernel Version 6.2 Update rc6
Linux ≫ Linux Kernel Version 6.2 Update rc7
Linux ≫ Linux Kernel Version 6.2 Update rc8
Linux ≫ Linux Kernel Version 6.2.0 Update rc1
Linux ≫ Linux Kernel Version 6.2.0 Update rc2
Linux ≫ Linux Kernel Version 6.2.0 Update rc3
Linux ≫ Linux Kernel Version 6.2.0 Update rc4
Linux ≫ Linux Kernel Version 6.2.0 Update rc5
Linux ≫ Linux Kernel Version 6.2.0 Update rc6
Linux ≫ Linux Kernel Version 6.6 Update rc1
Linux ≫ Linux Kernel Version 6.6 Update rc2
Linux ≫ Linux Kernel Version 6.6 Update rc3
Linux ≫ Linux Kernel Version 6.6 Update rc4
Linux ≫ Linux Kernel Version 6.6 Update rc5
Linux ≫ Linux Kernel Version 6.6 Update rc6
Fedoraproject ≫ Fedora Version 39
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.191
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
RedHat 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://access.redhat.com/security/cve/CVE-2023-5972
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2248189
Patch
Issue Tracking
https://github.com/torvalds/linux/commit/505ce0630ad5d31185695f8a29dde8d29f28faa7
Patch
https://github.com/torvalds/linux/commit/52177bbf19e6e9398375a148d2e13ed492b40b80
Patch