ZeroHour

CVE-2023-35788

PoC ×2
CVSS 3.1
7.8 high
EPSS
<1%p43
Published
()
Modified
Description

An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.

Vendors
linuxdebiannetappcanonical
Products
linux kernel, debian linux, h300s firmware, h500s firmware, h700s firmware, h410s firmware, h410c firmware, ubuntu linux
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.