Description
A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to cause a 4 byte out-of-bounds read of XFRMA_MTIMER_THRESH when parsing netlink attributes, leading to potential leakage of sensitive heap data to userspace.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3623-1 | linux-5.10 security update |
Debian DSA |
DSA-5492-1 | linux security update |
EUVD |
EUVD-2023-44406 | A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to cause a 4 byte out-of-bounds read of XFRMA_MTIMER_THRESH when parsing netlink attributes, leading to potential leakage of sensitive heap data to userspace. |
Ubuntu USN |
USN-6415-1 | Linux kernel (OEM) vulnerabilities |
Ubuntu USN |
USN-6534-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6534-2 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6534-3 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6549-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6549-2 | Linux kernel (GKE) vulnerabilities |
Ubuntu USN |
USN-6549-3 | Linux kernel (Low Latency) vulnerabilities |
Ubuntu USN |
USN-6549-4 | Linux kernel (Intel IoTG) vulnerabilities |
Ubuntu USN |
USN-6549-5 | Linux kernel vulnerabilities |
References
History
Wed, 05 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 16 Sep 2024 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-14T14:21:06.184Z
Reserved: 2023-07-19T13:55:13.694Z
Link: CVE-2023-3773
Updated: 2024-08-02T07:08:49.757Z
Status : Modified
Published: 2023-07-25T16:15:11.733
Modified: 2024-11-21T08:18:01.957
Link: CVE-2023-3773
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Ubuntu USN