CVE-2023-39192
published 2023-10-09CVE-2023-39192: A flaw was found in the Netfilter subsystem in the Linux kernel. The xt_u32 module did not validate the fields in the xt_u32 structure. This flaw allows a…
medium6CVSS 3.1
AVLACLPRHUINSUCHINAH
A flaw was found in the Netfilter subsystem in the Linux kernel. The xt_u32 module did not validate the fields in the xt_u32 structure. This flaw allows a local privileged attacker to trigger an out-of-bounds read by setting the size fields with a value beyond the array boundaries, leading to a crash or information disclosure.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.55-1 (bookworm) | linux 6.1.55-1 (bookworm) |
| fedoraproject | fedora | — | — |
| linux | linux_kernel | < 6.6 | 6.6 |
| linux | linux_kernel | >= 0 < 5.10.197-1 | 5.10.197-1 |
| linux | linux_kernel | >= 0 < 6.1.55-1 | 6.1.55-1 |
| linux | linux_kernel | >= 0 < 6.5.3-1 | 6.5.3-1 |
| linux | linux_kernel | >= 0 < 6.5.3-1 | 6.5.3-1 |
| linux | linux_kernel | >= 0 < 5.4.0-169.187 | 5.4.0-169.187 |
| linux | linux_kernel | >= 0 < 5.15.0-91.101 | 5.15.0-91.101 |
| linux | linux_kernel | >= 0 < 4.4.0-248.282 | 4.4.0-248.282 |
| linux | linux_kernel | >= 0 < 4.15.0-220.231 | 4.15.0-220.231 |
| msrc | cbl2_kernel_5.15.135.1-2_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
| ubuntu | linux-gcp | — | — |
| ubuntu | linux-kvm | — | — |
CVSS provenance
nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
osv6.0MEDIUM