Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-22024


In the Unbreakable Enterprise Kernel (UEK), the RDS module in UEK has two setsockopt(2) options, RDS_CONN_RESET and RDS6_CONN_RESET, that are not re-entrant. A malicious local user with CAP_NET_ADMIN can use this to crash the kernel. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).


Published

2023-09-20T21:15:11.143

Last Modified

2024-11-21T07:44:07.597

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application oracle vm_server 3.0 Yes
Operating System oracle linux 6 Yes
Operating System oracle linux 7 Yes
Operating System oracle linux 8 Yes
Operating System oracle linux 9 Yes

References