一、漏洞信息 漏洞编号:CVE-2023-3117 漏洞归属组件:kernel 漏洞归属的版本:4.19、5.10 CVSS V3.0分值: BaseScore:7.8 High Vector:CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 漏洞简述: A use-after-free flaw was found in the Netfilter subsystem of the Linux kernel when processing named and anonymous sets in batch requests, which can lead to performing arbitrary reads and writes in kernel memory. This flaw allows a local user with CAP_NET_ADMIN capability to crash or potentially escalate their privileges on the system. 漏洞公开时间:2023-07-01 06:15:00 漏洞创建时间:2023-06-30 06:39:34 漏洞详情参考链接: https://nvd.nist.gov/vuln/detail/CVE-2023-3117
The PR Link: https://gitee.com/anolis/cloud-kernel/pulls/2106
PR: https://gitee.com/anolis/cloud-kernel/pulls/2106