Bug 5988 - 【5.10】Bugfix for CVE-2023-32233
Summary: 【5.10】Bugfix for CVE-2023-32233
Status: RESOLVED FIXED
Alias: None
Product: ANCK 5.10 Dev
Classification: ANCK
Component: net (show other bugs) net
Version: unspecified
Hardware: All Linux
: P3-Medium S3-normal
Target Milestone: ---
Assignee: XuanZhuo
QA Contact: shuming
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-07-26 14:34 UTC by tangbinzy
Modified: 2023-10-19 11:43 UTC (History)
3 users (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description tangbinzy cmss_group 2023-07-26 14:34:01 UTC
一、漏洞信息
漏洞编号:CVE-2023-32233
漏洞归属组件:kernel
漏洞归属的版本:4.19、5.10
CVSS V3.0分值:
BaseScore:7.8 High
Vector:CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞简述:
In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.
漏洞公开时间:2023-05-09 04:15:00
漏洞创建时间:2023-05-09 00:44:22
漏洞详情参考链接:
https://nvd.nist.gov/vuln/detail/CVE-2023-32233
Comment 1 宁畅 alibaba_cloud_group 2023-10-19 11:43:25 UTC
已合入:https://gitee.com/anolis/cloud-kernel/pulls/1629