CVE-2023-1075
Description
A memory leak flaw was found in the Linux kernel's TLS protocol. This issue could allow a local user unauthorized access to some memory.
Mesure d'atténuation
To mitigate this issue, prevent module tls from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.
Détails du score du système commun d'évaluation des vulnérabilités (CVSS)
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
Répartition des scores CVSS v3
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Score de base | 3.3 | 3.3 | 3.3 |
| Vecteur d'attaque | Local | Local | Local |
| Complexité de l'attaque | Low | Low | Low |
| Privilèges requis | Low | Low | Low |
| Interaction avec l'utilisateur | None | None | None |
| Champ d'application | Unchanged | Unchanged | Unchanged |
| Confidentialité | Low | Low | Low |
| Impact sur l'intégrité | None | None | None |
| Impact sur la disponibilité | None | None | None |
Vecteur
Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
NVD: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
cve.org: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Comprendre la Défaillance (CWE)
Availability,Integrity,Confidentiality
Technical Impact: Read Memory; Modify Memory; Execute Unauthorized Code or Commands; DoS: Crash, Exit, or Restart
When a memory buffer is accessed using the wrong type, it could read or write memory out of the bounds of the buffer, if the allocated buffer is smaller than the type that the code is attempting to access, leading to a crash and possibly code execution.
Questions fréquemment posées
Not sure what something means? Check out our Security Glossary.
Vous souhaitez recevoir des notifications d'errata ? Signez ici.