5.5
CVSSv3

CVE-2023-6622

Published: 08/12/2023 Updated: 30/04/2024
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

An issue exists in the Linux kernel up to and including 6.5.9. During a race with SQ thread exit, an io_uring/fdinfo.c io_uring_show_fdinfo NULL pointer dereference can occur. (CVE-2023-46862) An out-of-bounds read vulnerability was found in the NVMe-oF/TCP subsystem in the Linux kernel. This flaw allows a remote malicious user to send a crafted TCP packet, triggering a heap-based buffer overflow that results in kmalloc data to be printed (and potentially leaked) to the kernel ring buffer (dmesg). (CVE-2023-6121) A null pointer dereference vulnerability was found in nft_dynset_init() in net/netfilter/nft_dynset.c in nf_tables in the Linux kernel. This issue may allow a local attacker with CAP_NET_ADMIN user privilege to trigger a denial of service. (CVE-2023-6622) A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The function nft_pipapo_walk did not skip inactive elements during set walk which could lead double deactivations of PIPAPO (Pile Packet Policies) elements, leading to use-after-free. We recommend upgrading past commit 317eb9685095678f2c9f5a8189de698c5354316a. (CVE-2023-6817) A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group(). We recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b. (CVE-2023-6931) A use-after-free vulnerability in the Linux kernel's ipv4: igmp component can be exploited to achieve local privilege escalation. A race condition can be exploited to cause a timer be mistakenly registered on a RCU read locked object which is freed by another thread. We recommend upgrading past commit e2b706c691905fe78468c361aaabc719d0a496f1. (CVE-2023-6932)

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 6.7

linux linux kernel

redhat enterprise linux 8.0

redhat enterprise linux 9.0

Vendor Advisories

An issue was discovered in the Linux kernel through 659 During a race with SQ thread exit, an io_uring/fdinfoc io_uring_show_fdinfo NULL pointer dereference can occur (CVE-2023-46862) An out-of-bounds read vulnerability was found in the NVMe-oF/TCP subsystem in the Linux kernel This flaw allows a remote attacker to send a crafted TCP packet, ...
An issue was discovered in the Linux kernel through 659 During a race with SQ thread exit, an io_uring/fdinfoc io_uring_show_fdinfo NULL pointer dereference can occur (CVE-2023-46862) An out-of-bounds read vulnerability was found in the NVMe-oF/TCP subsystem in the Linux kernel This flaw allows a remote attacker to send a crafted TCP packet, ...
Description<!---->A null pointer dereference vulnerability was found in nft_dynset_init() in net/netfilter/nft_dynsetc in nf_tables in the Linux kernel This issue may allow a local attacker with CAP_NET_ADMIN user privilege to trigger a denial of serviceA null pointer dereference vulnerability was found in nft_dynset_init() in net/netfilter/nft_ ...