6.7
CVSSv3

CVE-2024-0193

Published: 02/01/2024 Updated: 12/03/2024
CVSS v3 Base Score: 6.7 | Impact Score: 5.9 | Exploitability Score: 0.8
VMScore: 0

Vulnerability Summary

An out-of-bounds read vulnerability was found in smbCalcSize in fs/smb/client/netmisc.c in the Linux Kernel. This issue could allow a local malicious user to crash the system or leak internal kernel information. (CVE-2023-6606) A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, the element can be deactivated twice. This can cause a use-after-free issue on an NFT_CHAIN object or NFT_OBJECT object, allowing a local unprivileged user with CAP_NET_ADMIN capability to escalate their privileges on the system. (CVE-2024-0193)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel -

redhat enterprise linux 9.0

Vendor Advisories

An out-of-bounds read vulnerability was found in smbCalcSize in fs/smb/client/netmiscc in the Linux Kernel This issue could allow a local attacker to crash the system or leak internal kernel information (CVE-2023-6606) A use-after-free flaw was found in the netfilter subsystem of the Linux kernel If the catchall element is garbage-collected whe ...
An out-of-bounds read vulnerability was found in smbCalcSize in fs/smb/client/netmiscc in the Linux Kernel This issue could allow a local attacker to crash the system or leak internal kernel information (CVE-2023-6606) A use-after-free flaw was found in the netfilter subsystem of the Linux kernel If the catchall element is garbage-collected whe ...
Description<!----> This CVE is under investigation by Red Hat Product Security ...