CVE-2023-39194
published 2023-10-09CVE-2023-39194: A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past…
medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, potentially leading to an information disclosure.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.52-1 (bookworm) | linux 6.1.52-1 (bookworm) |
| fedoraproject | fedora | — | — |
| linux | linux_kernel | < 6.5 | 6.5 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.197-1 | 5.10.197-1 |
| linux | linux_kernel | >= 0 < 6.1.52-1 | 6.1.52-1 |
| linux | linux_kernel | >= 0 < 6.4.13-1 | 6.4.13-1 |
| linux | linux_kernel | >= 0 < 6.4.13-1 | 6.4.13-1 |
| linux | linux_kernel | >= 0 < 5.4.0-169.187 | 5.4.0-169.187 |
| linux | linux_kernel | >= 0 < 5.15.0-91.101 | 5.15.0-91.101 |
| linux | linux_kernel | >= 0 < 4.4.0-248.282 | 4.4.0-248.282 |
| linux | linux_kernel | >= 0 < 4.15.0-220.231 | 4.15.0-220.231 |
| msrc | cbl2_kernel_5.15.135.1-2_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| ubuntu | linux-gcp | — | — |
| ubuntu | linux-kvm | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM