CVE-2023-6932
Red Hat Security Advisory: kernel security and bug fix update
Description
A race condition has been discovered in the Linux kernel's Internet Group Management Protocol (IGMP) implementation. This vulnerability may enable an attacker to provoke an application crash or potentially escalate privileges locally. By exploiting the race condition, an adversary could disrupt the normal operation of affected systems, leading to service disruption or, in the worst case, unauthorized access to sensitive resources.
Metrics
Show all metrics
Included in the same advisory
- CVE-2024-0646
An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function…
— - CVE-2023-6817
A use-after-free flaw was found in the Netfilter subsystem in the Linux kernel via the nft_pipapo_walk function.
highCVSSv3 7.8 - CVE-2023-6610
An out-of-bounds read vulnerability was found in smb2_dump_detail in fs/smb/client/smb2ops.c in the Linux Kernel.
highCVSSv3 7.1 - CVE-2023-6536
A flaw was found in the Linux kernel's NVMe driver.
highCVSSv3 7.5 - CVE-2023-6535
A flaw was found in the Linux kernel's NVMe driver.
highCVSSv3 7.5 - CVE-2023-6356
A flaw was found in the Linux kernel's NVMe driver.
highCVSSv3 7.5 - CVE-2023-5717
A flaw was found in the Linux kernel's Performance Events system component.
— - CVE-2023-54270
A use-after-free vulnerability was found in the Linux kernel's Siano USB driver for digital TV receivers.
—CVSSv3 0.0 - CVE-2023-4921
A use-after-free flaw was found in qfq_dequeue and agg_dequeue in net/sched/sch_qfq.c in the Traffic Control (QoS) subsystem in the Linux…
— - CVE-2023-46813
A buffer overflow and null pointer dereference flaw was found in the Linux kernel's Secure Encrypted Virtualization (SEV) implementation…
— - CVE-2023-45862
An out-of-bounds memory access flaw was found in the Linux kernel ENE SD/MS Card reader driver.
— - CVE-2023-4132
A use-after-free vulnerability was found in the siano smsusb module in the Linux kernel.
— - CVE-2023-40283
A flaw was found in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Bluetooth subsystem in the Linux Kernel.
— - CVE-2023-35825
A race condition was found in the Linux kernel's r592 device driver, when removing the module before cleanup in the r592_remove function.
— - CVE-2023-3141
A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel.
— - CVE-2023-28772
A buffer overflow write flaw was identified in seq_buf_putmem_hex in lib/seq_buf.c in seq_buf in the Linux Kernel.
— - CVE-2023-28328
A NULL pointer dereference flaw was found in the az6027 driver in drivers/media/usb/dev-usb/az6027.c in the Linux Kernel.
— - CVE-2023-23455
A denial of service flaw was found in atm_tc_enqueue in net/sched/sch_atm.c in the Linux kernel.
— - CVE-2023-2176
A vulnerability was found in compare_netdev_and_ip in drivers/infiniband/core/cma.c in RDMA in the Linux kernel.
— - CVE-2023-2166
A NULL pointer dereference issue was found in the can protocol in net/can/af_can.c in the Linux kernel, where ml_priv may not be initiali…
— - CVE-2023-20569
A side channel vulnerability was found in hw amd.
— - CVE-2023-1989
A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel.
highCVSSv3 7.0 - CVE-2023-1252
A use-after-free flaw was found in the Linux kernel’s Ext4 File System in how a user triggers several file operations simultaneously with…
— - CVE-2023-1075
A memory leak flaw was found in the Linux kernel's TLS protocol.
—
Show 32 more CVEs
- CVE-2023-0458
A vulnerabilty was found in Linux Kernel, where a speculative pointer dereference problem exists in the Linux Kernel on the do_prlimit()…
— - CVE-2022-50272
In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb: az6027: fix null-ptr-deref in az6027_i2c_xfer() Wei…
—CVSSv3 0.0 - CVE-2022-50213
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: do not allow SET_ID to refer to another table…
highCVSSv3 7.8 - CVE-2022-49908
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix memory leak in vhci_write Syzkaller reports a…
mediumCVSSv3 5.5 - CVE-2022-45887
A memory leak issue was found in the Linux kernel media subsystem in the TTUSB DEC driver.
— - CVE-2022-39189
A flaw was found in the x86 KVM subsystem in kvm_steal_time_set_preempted in arch/x86/kvm/x86.c in the Linux kernel.
— - CVE-2022-3707
A double-free memory flaw was found in the Linux kernel.
— - CVE-2022-36946
A memory corruption flaw was found in the Linux kernel’s Netfilter subsystem in the way a local user uses the libnetfilter_queue when ana…
— - CVE-2022-3623
A vulnerability was found in follow_page_pte in mm/gup.c in the Linux Kernel.
— - CVE-2022-3619
A memory leak flaw was found in the Linux kernel’s L2CAP bluetooth functionality.
— - CVE-2022-3594
A vulnerability was found in intr_callback in drivers/net/usb/r8152.c in the BPF component in the Linux Kernel.
mediumCVSSv3 5.3 - CVE-2022-3566
A vulnerability was found in the tcp subsystem in the Linux Kernel, due to a data race around icsk->icsk_af_ops.
highCVSSv3 7.1 - CVE-2022-3545
A vulnerability was found in area_cache_get in drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c in the Netronome Flow Processor (…
mediumCVSSv3 5.5 - CVE-2022-3524
A memory leak flaw was found in the Linux kernel’s IPv6 functionality in how a user triggers the setsockopt of the IPV6_ADDRFORM and IPV6…
mediumCVSSv3 4.3 - CVE-2022-28893
A use-after-free flaw was found in the Linux kernel’s net/sunrpc/xprt.c function in the Remote Procedure Call (SunRPC) protocol.
— - CVE-2022-28390
A double-free flaw was found in the Linux kernel in the ems_usb_start_xmit function.
highCVSSv3 7.8 - CVE-2022-28388
A double-free flaw was found in the Linux kernel's USB2CAN interface implementation.
— - CVE-2022-2663
A flaw was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and it incorrectly matches on the mes…
— - CVE-2022-2586Actively exploited
A use-after-free flaw was found in nf_tables cross-table in the net/netfilter/nf_tables_api.c function in the Linux kernel.
criticalCVSSv3 7.8 - CVE-2022-25265
A vulnerability was found in the Linux kernel when certain binary files have the exec-all attribute with gcc.
— - CVE-2022-24448
A flaw was found in the Linux kernel.
— - CVE-2022-23222
A flaw was found in the Linux kernel's adjust_ptr_min_max_vals in the kernel/bpf/verifier.c function.
— - CVE-2022-21499
A flaw was found in the kernel/debug/debug_core.c in the Linux kernel in lockdown mode.
mediumCVSSv3 6.7 - CVE-2022-2078
A vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() function .This flaw allows an attacker to trigger a buffer ov…
— - CVE-2022-1462
An out-of-bounds read flaw was found in the Linux kernel’s TeleTYpe subsystem.
— - CVE-2022-0617
A NULL pointer dereference was found in the Linux kernel’s UDF file system functionality in the way the user triggers the udf_file_write_…
— - CVE-2022-0500
A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s B…
highCVSSv3 7.8 - CVE-2022-0168
A denial of service (DOS) issue was found in the Linux kernel’s smb2_ioctl_query_info function in the fs/cifs/smb2ops.c Common Internet F…
— - CVE-2021-4204
An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation.
— - CVE-2021-3640
A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGIST…
— - CVE-2021-34866
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.14-rc3.
highCVSSv3 8.8 - CVE-2021-30002
A flaw memory leak in the Linux kernel webcam device functionality was found in the way user calls ioctl that triggers video_usercopy fun…
—