Kernel: nvme: info leak due to out-of-bounds read in nvmet_ctrl_find_get
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 4.3epss 1.7%
probabilidade de exploração
1.7%top 24% das CVEs
exploração observada
nãonenhuma fonte reporta
An out-of-bounds read vulnerability was found in the NVMe-oF/TCP subsystem in the Linux kernel. This issue may allow a remote attacker to send a crafted TCP packet, triggering a heap-based buffer overflow that results in kmalloc data being printed and potentially leaked to the kernel ring buffer (dmesg).
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Produtos afetados
Red Hat · Red Hat Enterprise Linux 6Red Hat · Red Hat Enterprise Linux 7Red Hat · Red Hat Enterprise Linux 8Red Hat · Red Hat Enterprise Linux 9Referências
https://access.redhat.com/errata/RHSA-2024:2394https://access.redhat.com/errata/RHSA-2024:2950https://access.redhat.com/errata/RHSA-2024:3138https://access.redhat.com/security/cve/CVE-2023-6121https://bugzilla.redhat.com/show_bug.cgi?id=2250043https://cert-portal.siemens.com/productcert/html/ssa-265688.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-398330.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-613116.htmlhttps://lists.debian.org/debian-lts-announce/2024/01/msg00005.html