CVE-2023-52429
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2023-52429 is a newly disclosed vulnerability affecting the Linux kernel version up to 6.7.4. The issue lies within the dm_table_create function in the dm-table.c file of the Linux kernel driver. An attacker can exploit this flaw by trying to allocate more memory than the maximum limit (INT_MAX) in the alloc_targets function. Consequently, the system may crash due to a missing check for struct dm_ioctl.target_count. Successful exploitation of this vulnerability could result in a denial-of-service condition. System administrators are recommended to upgrade their Linux kernel to a patched version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.