A NULL pointer dereference vulnerability was found in netlink_dump. This issue can occur when the Netlink socket receives the message(sendmsg) for the XFRM_MSG_GETSA, XFRM_MSG_GETPOLICY type message, and the DUMP flag is set and can cause a denial of service or possibly another unspecified impact. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is unlikely.
History

Tue, 03 Dec 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2023-07-12T08:27:58.635Z

Updated: 2024-12-03T15:20:56.382Z

Reserved: 2023-06-05T13:55:28.745Z

Link: CVE-2023-3106

cve-icon Vulnrichment

Updated: 2024-08-02T06:48:07.201Z

cve-icon NVD

Status : Modified

Published: 2023-07-12T09:15:14.550

Modified: 2024-11-21T08:16:28.270

Link: CVE-2023-3106

cve-icon Redhat

Severity : Moderate

Publid Date: 2016-07-18T00:00:00Z

Links: CVE-2023-3106 - Bugzilla