Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian 10: DSA-5453-1 Moderate: Linux Kernel Privilege Escalation

debian
Calendar Grey July 16, 2023
Debian Logo
Multiple Debian Linux kernel vulnerabilities may result in escalation, denial of service, or data breaches. Update is advised.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks

Summary

CVE-2023-2156

It was discovered that a flaw in the handling of the RPL protocol
may allow an unauthenticated remote attacker to cause a denial of
service if RPL is enabled (not by default in Debian).

CVE-2023-31248

Mingi Cho discovered a use-after-free flaw in the Netfilter
nf_tables implementation when using nft_chain_lookup_byid, which may
result in local privilege escalation for a user with the
CAP_NET_ADMIN capability in any user or network namespace.

CVE-2023-35001

Tanguy DUBROCA discovered an out-of-bounds reads and write flaw in
the Netfilter nf_tables implementation when processing an
nft_byteorder expression, which may result in local privilege
escalation for a user with the CAP_NET_ADMIN capability in any user
or network namespace.

For the oldstable distribution (bullseye), these problems have been fixed
in version 5.10.179-2.

We recommend that you upgrade your linux packages.

For the detailed security status of linux please refer to its security
...

Read the Full Advisory

Package: linux
CVE ID: CVE-2023-2156 CVE-2023-31248 CVE-2023-35001

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here