Tracker / CVE-2023-3106
CVE-2023-3106
Medium 6.6
A NULL pointer dereference vulnerability was found in netlink_dump. This issue can occur when the Netlink socket receives the message(sendmsg) for the XFRM_MSG_GETSA, XFRM_MSG_GETPOLICY type message, and the DUMP flag is set and can cause a denial of service or possibly another unspecified impact. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is unlikely.
Affected products and versions
| fedoraproject | fedora |
|---|---|
| linux | linux_kernel |
| linux | linux_kernel · 3.15 → 3.16.39 |
| linux | linux_kernel · 3.17 → 4.4.223 |
| linux | linux_kernel · 4.5 → 4.7.10 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.