CVE-2023-2176

ECS: Out-of-bounds Read (CVE-2023-2176)

Affected

  • Dell/ECS 3.8.1.0..*

Description

A vulnerability was found in compare_netdev_and_ip in drivers/infiniband/core/cma.c in RDMA in the Linux kernel. An improper cleanup results in an out-of-boundary read. This flaw allows a local user to crash or escalate privileges on the system.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

DellECS
3.8.1.0

Metrics

13.7 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
none
no public PoC known
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2023-04-20 00:00 UTC
CWE-125

Weakness classes (CWE)

  • CWE-125Base

    Out-of-bounds Read

    The product reads data past the end, or before the beginning, of the intended buffer.

    cwe.mitre.org →

References & sources