CVE-2023-1075

Description

A memory leak flaw was found in the Linux kernel's TLS protocol. This issue could allow a local user unauthorized access to some memory.

Mesure d'atténuation

To mitigate this issue, prevent module tls from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.

Détails du score du système commun d'évaluation des vulnérabilités (CVSS)

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

Répartition des scores CVSS v3

Red HatNVDcve.org
Score de base3.33.33.3
Vecteur d'attaqueLocalLocalLocal
Complexité de l'attaqueLowLowLow
Privilèges requisLowLowLow
Interaction avec l'utilisateurNoneNoneNone
Champ d'applicationUnchangedUnchangedUnchanged
ConfidentialitéLowLowLow
Impact sur l'intégritéNoneNoneNone
Impact sur la disponibilitéNoneNoneNone

Vecteur

Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

NVD: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

cve.org: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Comprendre la Défaillance (CWE)

Availability,Integrity,Confidentiality

Technical Impact: Read Memory; Modify Memory; Execute Unauthorized Code or Commands; DoS: Crash, Exit, or Restart

When a memory buffer is accessed using the wrong type, it could read or write memory out of the bounds of the buffer, if the allocated buffer is smaller than the type that the code is attempting to access, leading to a crash and possibly code execution.

Questions fréquemment posées

Vous souhaitez recevoir des notifications d'errata ? Signez ici.