7
CVSSv3

CVE-2023-6931

Published: 19/12/2023 Updated: 01/02/2024
CVSS v3 Base Score: 7 | Impact Score: 5.9 | Exploitability Score: 1
VMScore: 0

Vulnerability Summary

An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables: Reject tables of unsupported family); While creating a new netfilter table, lack of a safeguard against invalid nf_tables family (pf) values within `nf_tables_newtable` function enables an malicious user to achieve out-of-bounds access. (CVE-2023-6040) A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group(). We recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b. (CVE-2023-6931)

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

debian debian linux 10.0

Vendor Advisories

An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables: Reject tables of unsupported family); While creating a new netfilter table, lack of a safeguard against invalid nf_tables family (pf) values within `nf_tables_newtable` function enables an attacker to achieve out-of-bounds access ...
Description<!----> This CVE is under investigation by Red Hat Product Security ...
An issue was discovered in the Linux kernel through 659 During a race with SQ thread exit, an io_uring/fdinfoc io_uring_show_fdinfo NULL pointer dereference can occur (CVE-2023-46862) An out-of-bounds read vulnerability was found in the NVMe-oF/TCP subsystem in the Linux kernel This flaw allows a remote attacker to send a crafted TCP packet, ...
An out-of-bounds read vulnerability was found in the NVMe-oF/TCP subsystem in the Linux kernel This flaw allows a remote attacker to send a crafted TCP packet, triggering a heap-based buffer overflow that results in kmalloc data to be printed (and potentially leaked) to the kernel ring buffer (dmesg) (CVE-2023-6121) A heap out-of-bounds write vul ...
A race condition leading to a use-after-free issue was found in the QXL driver in the Linux kernel (CVE-2023-39198) An issue was discovered in the Linux kernel through 659 During a race with SQ thread exit, an io_uring/fdinfoc io_uring_show_fdinfo NULL pointer dereference can occur (CVE-2023-46862) An out-of-bounds read vulnerability was foun ...
A race condition leading to a use-after-free issue was found in the QXL driver in the Linux kernel (CVE-2023-39198) An issue was discovered in the Linux kernel through 659 During a race with SQ thread exit, an io_uring/fdinfoc io_uring_show_fdinfo NULL pointer dereference can occur (CVE-2023-46862) An out-of-bounds read vulnerability was foun ...
An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables: Reject tables of unsupported family); While creating a new netfilter table, lack of a safeguard against invalid nf_tables family (pf) values within `nf_tables_newtable` function enables an attacker to achieve out-of-bounds access ...
An issue was discovered in the Linux kernel through 659 During a race with SQ thread exit, an io_uring/fdinfoc io_uring_show_fdinfo NULL pointer dereference can occur (CVE-2023-46862) An out-of-bounds read vulnerability was found in the NVMe-oF/TCP subsystem in the Linux kernel This flaw allows a remote attacker to send a crafted TCP packet, ...
LTS-114&nbsp;is being updated in the LTS channel to&nbsp;11405735351 (Platform Version: 15437910)&nbsp;for most ChromeOS devices&nbsp;Want to know more about Long Term Support? Click&nbsp;hereThis update contains selective Security fixes, including:[40945671]&nbsp; &nbsp; &nbsp;High&nbsp;&nbsp;CVE-2024-0807&nbsp;Use after free in WebAudio[40 ...