A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to cause a 4 byte out-of-bounds read of XFRMA_MTIMER_THRESH when parsing netlink attributes, leading to potential leakage of sensitive heap data to userspace.
History

Mon, 16 Sep 2024 11:45:00 +0000


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2023-07-25T15:47:40.391Z

Updated: 2024-09-16T11:03:51.562Z

Reserved: 2023-07-19T13:55:13.694Z

Link: CVE-2023-3773

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-07-25T16:15:11.733

Modified: 2024-09-16T11:15:12.553

Link: CVE-2023-3773

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-07-23T00:00:00Z

Links: CVE-2023-3773 - Bugzilla