UBUNTU-CVE-2023-3773
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-3773
UBUNTU-CVE-2023-3773
Summary:
Details: A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to cause a 4 byte out-of-bounds read of XFRMA_MTIMER_THRESH when parsing netlink attributes, leading to potential leakage of sensitive heap data to userspace.
References: https://ubuntu.com/security/CVE-2023-3773, https://lore.kernel.org/all/[email protected]/T/#u, https://access.redhat.com/security/cve/CVE-2023-3773, https://ubuntu.com/security/notices/USN-6415-1, https://ubuntu.com/security/notices/USN-6534-1, https://ubuntu.com/security/notices/USN-6549-1, https://ubuntu.com/security/notices/USN-6534-2, https://ubuntu.com/security/notices/USN-6549-2, https://ubuntu.com/security/notices/USN-6534-3, https://ubuntu.com/security/notices/USN-6549-3, https://ubuntu.com/security/notices/USN-6549-4, https://ubuntu.com/security/notices/USN-6549-5, https://www.cve.org/CVERecord?id=CVE-2023-3773
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/linux-hwe-edge?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
