An out-of-bounds read vulnerability was found in the SR-IPv6 implementation in the Linux kernel. The flaw exists within the processing of seg6 attributes. The issue results from the improper validation of user-supplied data, which can result in a read past the end of an allocated buffer. This flaw allows a privileged local user to disclose sensitive information on affected installations of the Linux kernel.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 05 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-03-05T18:47:56.873Z

Reserved: 2023-05-24T07:11:24.194Z

Link: CVE-2023-2860

cve-icon Vulnrichment

Updated: 2024-08-02T06:33:05.705Z

cve-icon NVD

Status : Modified

Published: 2023-07-24T16:15:11.293

Modified: 2024-11-21T07:59:26.373

Link: CVE-2023-2860

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-09-05T00:00:00Z

Links: CVE-2023-2860 - Bugzilla

cve-icon OpenCVE Enrichment

No data.