CVE-2023-28772
Dell ECS: Sicherheitsluecke
noneEPSS 0.7%
Affected
- Dell/ECS
3.8.1.0..*
Description
A buffer overflow write flaw was identified in seq_buf_putmem_hex in lib/seq_buf.c in seq_buf in the Linux Kernel. This issue may allow a user with special debug privileges such as ftrace or root to cause an overflow in the destination buffer due to a missing sanity check.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
DellECS
3.8.1.0Metrics
Show all metrics
Severity
none
24.22
no public PoC known
Published
2023-03-23 00:00 UTC
References & sources
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13.3
- https://github.com/torvalds/linux/commit/d3b16034a24a112bb83aeb669ac5b9b01f744bb7
- https://lore.kernel.org/lkml/20210625122453.5e2fe304%40oasis.local.home/
- https://lkml.kernel.org/r/20210626032156.47889-1-yun.zhou%40windriver.com
- https://security.netapp.com/advisory/ntap-20230427-0005/