发布于3月6日3月6日 Members Red Hat: CVE-2023-3090: out-of-bounds write caused by unclear skb->cb (Multiple Advisories) Severity 7 CVSS (AV:L/AC:L/Au:S/C:C/I:C/A:C) Published 06/28/2023 Created 08/02/2023 Added 08/02/2023 Modified 01/28/2025 Description A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation. The out-of-bounds write is caused by missing skb->cbinitialization in the ipvlan network driver. The vulnerability is reachable if CONFIG_IPVLAN is enabled. We recommend upgrading past commit 90cbed5247439a966b645b34eb0a2e037836ea8e. Solution(s) redhat-upgrade-kernel redhat-upgrade-kernel-rt References CVE-2023-3090 RHSA-2023:4377 RHSA-2023:4378 RHSA-2023:4380 RHSA-2023:4801 RHSA-2023:4814 RHSA-2023:4828 RHSA-2023:5221 RHSA-2023:5244 RHSA-2023:5255 RHSA-2023:5548 RHSA-2023:5627 View more
参与讨论
你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。