Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于X86 CPU的cpu_entry_area映射中存在未授权内存访问漏洞。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 6 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
unaffected |
any |
unaffected | ||
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
any |
affected | ||
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | SCTF 2023 kernel pwn && CVE-2023-3640 | https://github.com/pray77/CVE-2023-3640 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-3812 | 7.8 HIGH | Kernel: tun: bugs for oversize packet when napi frags enabled in tun_napi_alloc_frags |
| CVE-2023-38200 | 7.5 HIGH | Keylime: registrar is subject to a dos against ssl connections |
| CVE-2023-3567 | 7.1 HIGH | Kernel: use after free in vcs_read in drivers/tty/vt/vc_screen.c due to race |
| CVE-2023-33952 | 6.7 MEDIUM | Kernel: vmwgfx: double free within the handling of vmw_buffer_object objects |
| CVE-2023-33951 | 6.7 MEDIUM | Kernel: vmwgfx: race condition leading to information disclosure vulnerability |
| CVE-2023-3750 | 6.5 MEDIUM | Libvirt: improper locking in virstoragepoolobjlistsearch may lead to denial of service |
| CVE-2023-3019 | 6.0 MEDIUM | Qemu: e1000e: heap use-after-free in e1000e_write_packet_to_guest() |
| CVE-2023-3745 | 5.5 MEDIUM | Imagemagick: heap-buffer-overflow in pushcharpixel() in quantum-private.h |
| CVE-2023-3384 | 5.4 MEDIUM | Quay: stored cross site scripting |
No comments yet