An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitrarily increment/decrement a memory buffer out-of-bound. This issue may allow a local user to crash the system or potentially escalate their privileges on the system.
2023-09-25T21:15:15.923
2024-11-21T08:23:06.080
Modified
CVSSv3.1: 7.0 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | < 4.5 | Yes |
Operating System | linux | linux_kernel | < 4.10 | Yes |
Operating System | linux | linux_kernel | < 4.15 | Yes |
Operating System | linux | linux_kernel | < 4.19.295 | Yes |
Operating System | linux | linux_kernel | < 5.4.257 | Yes |
Operating System | linux | linux_kernel | < 5.10.195 | Yes |
Operating System | linux | linux_kernel | < 5.15.132 | Yes |
Operating System | linux | linux_kernel | < 6.1.53 | Yes |
Operating System | linux | linux_kernel | < 6.4.16 | Yes |
Operating System | linux | linux_kernel | < 6.5.3 | Yes |
Operating System | redhat | enterprise_linux | 7.0 | Yes |
Operating System | redhat | enterprise_linux | 8.0 | Yes |
Operating System | redhat | enterprise_linux | 9.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |