An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the pr…
High CVSS 7.0
Summary
An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitrarily increment/decrement a memory buffer out-of-bound. This issue may allow a local user to crash the system or potentially escalate their privileges on the system.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
- :
- :
Lint boundary warnings (1)
The following non-blocking warnings were raised during the lint phase of this triage (e.g. reference URLs not yet on the allowlist). They do not affect entry usability and are disclosed for transparency (see DR-002).
-
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: http://packetstormsecurity.com/files/175963/Kernel-Live-Patch-Security-Notice-LSN-0099-1.html
Sources
- NVD DATABASE
Original Links
- https://access.redhat.com/errata/RHSA-2023:7370 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7379 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7382 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7389 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7411 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7418 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7539 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7558 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0089 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0113 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0134 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0340 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0346 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0347 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0371 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0376 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0378 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0402 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0403 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0412 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0461 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0562 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0563 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0593 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0999 Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-42753 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2239843 Issue Tracking
- https://seclists.org/oss-sec/2023/q3/216 Exploit
- http://packetstormsecurity.com/files/175963/Kernel-Live-Patch-Security-Notice-LSN-0099-1.html
- https://access.redhat.com/errata/RHSA-2023:7370 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7379 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7382 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7389 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7411 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7418 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7539 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7558 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0089 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0113 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0134 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0340 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0346 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0347 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0371 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0376 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0378 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0402 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0403 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0412 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0461 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0562 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0563 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0593 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0999 Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-42753 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2239843 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html
- https://lists.debian.org/debian-lts-announce/2024/01/msg00004.html
- https://seclists.org/oss-sec/2023/q3/216 Exploit
- https://www.openwall.com/lists/oss-security/2023/09/22/10
Timeline
- nvd_ingest NVD