Updated: 2023-07-22 03:12:26.690138
Description:
A NULL pointer dereference vulnerability was found in netlink_dump. This issue can occur when the Netlink socket receives the message(sendmsg) for the XFRM_MSG_GETSA, XFRM_MSG_GETPOLICY type message, and the DUMP flag is set and can cause a denial of service or possibly another unspecified impact. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is unlikely.
Links | NIST | CIRCL | RHEL | Ubuntu |
Severity | Score | |
---|---|---|
CVSS Version 2.x | 0 | |
CVSS Version 3.x | HIGH | 7.8 |
OS name | Project name | Version | Score | Severity | Status | Errata | Last updated |
---|---|---|---|---|---|---|---|
CentOS 6 ELS | kernel | 2.6.32 | 7.8 | HIGH | Needs Triage | 2023-07-22 00:21:44 | |
CentOS 7 ELS | kernel | 3.10.0 | 7.8 | HIGH | Needs Triage | 2023-09-18 17:13:35 | |
CloudLinux 6 ELS | kernel | 2.6.32 | 7.8 | HIGH | Not Vulnerable | 2023-09-19 11:09:07 | |
Oracle Linux 6 ELS | kernel | 2.6.32 | 7.8 | HIGH | Needs Triage | 2023-07-22 00:21:46 | |
Ubuntu 16.04 ELS | linux | 4.4.0 | 7.8 | HIGH | Released | 2023-07-24 11:05:48 |