ZeroHour

CVE-2023-3772

CVSS 3.1
4.4 medium
EPSS
<1%p38
Published
()
Modified
Description

A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of service.

Vendors
redhatfedoraprojectlinuxdebian
Products
enterprise linux, enterprise linux for real time, enterprise linux for real time for nfv, fedora, linux kernel, debian linux
Weakness
CWE-476
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.