cbcvebase.
CVE-2023-0179
published 2023-03-27

CVE-2023-0179: A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses…

PriorityP344high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
1.94%
77.9th percentile
A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root user via arbitrary code execution.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianlinux< linux 6.1.7-1 (bookworm)linux 6.1.7-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
linuxlinux
linuxlinux>= f6ae9f120dada00abfb47313364c35118469455f < 550efeff989b041f3746118c0ddd863c39ddc1aa550efeff989b041f3746118c0ddd863c39ddc1aa
linuxlinux>= f6ae9f120dada00abfb47313364c35118469455f < a8acfe2c6fb99f9375a9325807a179cd8c32e6e3a8acfe2c6fb99f9375a9325807a179cd8c32e6e3
linuxlinux>= f6ae9f120dada00abfb47313364c35118469455f < 76ef74d4a379faa451003621a84e3498044e7aa376ef74d4a379faa451003621a84e3498044e7aa3
linuxlinux>= f6ae9f120dada00abfb47313364c35118469455f < 696e1a48b1a1b01edad542a1ef293665864a4dd0696e1a48b1a1b01edad542a1ef293665864a4dd0
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.162-15.10.162-1
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 0 < 5.15.0-67.745.15.0-67.74
linuxlinux_kernel>= 0 < 4.15.0-206.2174.15.0-206.217
linuxlinux_kernel>= 0 < 5.4.0-144.1615.4.0-144.161
linuxlinux_kernel>= 0 < 5.15.0-67.745.15.0-67.74
linuxlinux_kernel>= 5.11 < 5.15.895.15.89
linuxlinux_kernel>= 5.16 < 6.1.76.1.7
linuxlinux_kernel>= 5.5 < 5.10.1645.10.164

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.