CVE-2023-39193

CVSS 3.1 Score 6.0 of 10 (medium)

Details

Published Oct 9, 2023
Updated: May 22, 2024
CWE ID 125

Summary

CVE-2023-39193 is a vulnerability affecting the Netfilter subsystem in the Linux kernel. The sctp_mt_check function fails to validate the flag_count field, enabling a local, privileged (CAP_NET_ADMIN) attacker to initiate an out-of-bounds read. This issue can result in a system crash or unintended data disclosure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share