← Back

CVE-2023-3106

nvd nist
Published: Jul 12, 2023Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A NULL pointer dereference vulnerability was found in netlink_dump. This issue can occur when the Netlink socket receives the message(sendmsg) for the XFRM_MSG_GETSA, XFRM_MSG_GETPOLICY type message, and the DUMP flag is set and can cause a denial of service or possibly another unspecified impact. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is unlikely.

Affected (10)

1 product
Linux Kernel
1 product
Fedora
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Linux
From 3.15 to 3.16.39
From 3.17 to 4.4.223
From 4.5 to 4.7.10
Version 4.8 rc1
Version 4.8 rc2
Version 4.8 rc3
Version 4.8 rc4
Version 4.8 rc5
Version 4.8 rc6
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 38

References (6)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory

Timeline

No history available yet.