CVE-2023-2860

medium

Description

An out-of-bounds read vulnerability was found in the SR-IPv6 implementation in the Linux kernel. The flaw exists within the processing of seg6 attributes. The issue results from the improper validation of user-supplied data, which can result in a read past the end of an allocated buffer. This flaw allows a privileged local user to disclose sensitive information on affected installations of the Linux kernel.

References

https://www.zerodayinitiative.com/advisories/ZDI-CAN-18511

https://bugzilla.redhat.com/show_bug.cgi?id=2218122

https://access.redhat.com/security/cve/CVE-2023-2860

Details

Source: Mitre, NVD

Published: 2023-07-24

Updated: 2023-11-07

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:L/AC:L/Au:M/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 4.4

Vector: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Severity: Medium