CVE-2023-22024
Summary
| CVE | CVE-2023-22024 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-20 21:15:00 UTC |
| Updated | 2023-09-25 16:09:00 UTC |
| Description | In the Unbreakable Enterprise Kernel (UEK), the RDS module in UEK has two setsockopt(2) options, RDS_CONN_RESET and RDS6_CONN_RESET, that are not re-entrant. A malicious local user with CAP_NET_ADMIN can use this to crash the kernel. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| linux.oracle.com | CVE-2023-22024 | MISC | linux.oracle.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160913 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2023-12800)
- 160914 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2023-12799)
- 160915 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2023-12798)
- 160916 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel-container (ELSA-2023-12802)
- 160917 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2023-12803)
- 160918 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel-container (ELSA-2023-12801)
- 160949 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2023-12842)
- 160963 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2023-12858)
- 160977 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2023-12875)
- 160978 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2023-12874)
- 160982 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel-container (ELSA-2023-12911)
- 160985 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel-container (ELSA-2023-12910)
- 390288 Oracle Managed Virtualization (VM) Server for x86 Security Update for kernel (OVMSA-2023-0021)
- 390290 Oracle Managed Virtualization (VM) Server for x86 Security Update for kernel (OVMSA-2023-0023)