Description of problem: 一、漏洞信息 漏洞编号:CVE-2023-3772 漏洞归属组件:kernel 二、漏洞简述: A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of service. 漏洞公开时间:2023-07-26 00:15:00 漏洞创建时间:2023-07-26 00:48:38 漏洞详情参考链接: https://nvd.nist.gov/vuln/detail/CVE-2023-3772
The PR Link: https://gitee.com/anolis/cloud-kernel/pulls/2184