All errata/sisyphus_riscv64/ALT-PU-2023-2535-1
ALT-PU-2023-2535-1

Package update kernel-image-un-def in branch sisyphus_riscv64

Version6.1.11-alt1.0.rv64
Task#0
Published2023-02-13
Max severityMEDIUM
Severity:

Closed issues (2)

BDU:2023-02624
MEDIUM6.7

Уязвимость реализации сетевого протокола NET/ROM ядра операционной системы Linux, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность данных.

Published: 2023-05-17Modified: 2025-02-27
CVSS 3.xMEDIUM 6.7
CVSS:3.x/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.0MEDIUM 6.5
CVSS:2.0/AV:L/AC:L/Au:M/C:C/I:C/A:C
References
CVE-2023-32269
MEDIUM6.7

An issue was discovered in the Linux kernel before 6.1.11. In net/netrom/af_netrom.c, there is a use-after-free because accept is also allowed for a successfully connected AF_NETROM socket. However, in order for an attacker to exploit this, the system must have netrom routing configured or the attacker must have the CAP_NET_ADMIN capability.

Published: 2023-05-05Modified: 2025-05-05
CVSS 3.xMEDIUM 6.7
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H