CVE-2023-39189
Summary
| CVE | CVE-2023-39189 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-09 18:15:00 UTC |
| Updated | 2023-11-07 04:17:00 UTC |
| Description | A flaw was found in the Netfilter subsystem in the Linux kernel. The nfnl_osf_add_callback function did not validate the user mode controlled opt_num field. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, leading to a crash or information disclosure. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| cve-details |
MISC |
access.redhat.com |
|
| 2226777 – (CVE-2023-39189, ZDI-CAN-18745) CVE-2023-39189 kernel: netfilter: nftables out-of-bounds read in nf_osf_match_one() |
MISC |
bugzilla.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199881 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6461-1)
- 199936 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6494-1)
- 199970 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6494-2)
- 199976 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6534-1)
- 199979 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6532-1)
- 199980 Ubuntu Security Notification for Linux kernel Vulnerability (USN-6536-1)
- 199982 Ubuntu Security Notification for Linux kernel (GCP) Vulnerability (USN-6537-1)
- 199996 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6549-1)
- 199997 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6548-1)
- 199999 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6548-2)
- 200002 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6534-2)
- 200003 Ubuntu Security Notification for Linux kernel (GKE) Vulnerabilities (USN-6549-2)
- 200006 Ubuntu Security Notification for Linux kernel (Oracle) Vulnerabilities (USN-6548-3)
- 200007 Ubuntu Security Notification for Linux kernel (Low Latency) Vulnerabilities (USN-6549-3)
- 200010 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6534-3)
- 200024 Ubuntu Security Notification for Linux kernel (Intel IoTG) Vulnerabilities (USN-6549-4)
- 200035 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6549-5)
- 200037 Ubuntu Security Notification for Linux kernel (IoT) Vulnerabilities (USN-6548-5)
- 200113 Ubuntu Security Notification for Linux kernel (GCP) Vulnerabilities (USN-6635-1)
- 6000429 Debian Security Update for linux (DLA 3710-1)
- 673534 EulerOS Security Update for kernel (EulerOS-SA-2024-1086)
- 673595 EulerOS Security Update for kernel (EulerOS-SA-2023-3247)
- 673644 EulerOS Security Update for kernel (EulerOS-SA-2023-3336)
- 673692 EulerOS Security Update for kernel (EulerOS-SA-2023-3275)
- 673923 EulerOS Security Update for kernel (EulerOS-SA-2024-1062)
- 673995 EulerOS Security Update for kernel (EulerOS-SA-2024-1275)
- 674042 EulerOS Security Update for kernel (EulerOS-SA-2023-3304)
- 755235 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4377-1)
- 755238 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4378-1)
- 755240 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4375-1)
- 755249 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4414-1)
- 755563 SUSE Security Update for the linux kernel (SUSE-SU-2023:4351-1)
- 755564 SUSE Security Update for the linux kernel (SUSE-SU-2023:4348-1)
- 755565 SUSE Security Update for the linux kernel (SUSE-SU-2023:4347-1)
- 755566 SUSE Security Update for the linux kernel (SUSE-SU-2023:4345-1)
- 755567 SUSE Security Update for the linux kernel (SUSE-SU-2023:4343-1)
- 907471 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (31267)
- 907589 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (31267-1)