🪟 Windows TippsHP Announces an AMD-Powered Portable Workstation(16.09.2026 um 01:59 Uhr)
🔧 ProgrammierungWhat I Actually Learned Adding Asgardeo Login to a Side Project(16.09.2026 um 01:27 Uhr)
🔧 ProgrammierungAnanthika Unlocks Athena: SQL Wisdom Without a Single Server ⚡(16.09.2026 um 01:27 Uhr)
🔧 ProgrammierungAWS Transit Gateway (TGW)(16.09.2026 um 01:30 Uhr)
🔧 ProgrammierungBuilding Answer Lineage for Enterprise Data Agents(16.09.2026 um 01:45 Uhr)
🔧 ProgrammierungThe Hacker Who Lost $7.73M to a Bot — rsETH Safe Module Exploit(16.09.2026 um 01:49 Uhr)
🔧 ProgrammierungSummaries drift. Facts should not.(16.09.2026 um 01:59 Uhr)
🪟 Windows TippsHP Announces an AMD-Powered Portable Workstation(16.09.2026 um 01:59 Uhr)
🔧 ProgrammierungWhat I Actually Learned Adding Asgardeo Login to a Side Project(16.09.2026 um 01:27 Uhr)
🔧 ProgrammierungAnanthika Unlocks Athena: SQL Wisdom Without a Single Server ⚡(16.09.2026 um 01:27 Uhr)
🔧 ProgrammierungAWS Transit Gateway (TGW)(16.09.2026 um 01:30 Uhr)
🔧 ProgrammierungBuilding Answer Lineage for Enterprise Data Agents(16.09.2026 um 01:45 Uhr)
🔧 ProgrammierungThe Hacker Who Lost $7.73M to a Bot — rsETH Safe Module Exploit(16.09.2026 um 01:49 Uhr)
🔧 ProgrammierungSummaries drift. Facts should not.(16.09.2026 um 01:59 Uhr)

🐧 Unix Server 🕛 vor 2 Jahren 3 Min Lesezeit CVE-2023-1206
0

USN-6439-1: Linux kernel vulnerabilities

Cyber Threat & Vulnerability Dossier CVSS 5.8 MEDIUM (Heuristik) EPSS 5.8%
ANGRIPPSVEKTOR
💻 Lokal
AUTHENTIFIZIERUNG
🔓 Keine Authentifizierung nötig
SCHADENSPROFIL
⛔ Dienstausfall (DoS) / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-119: Memory Corruption
Handlungsempfehlung: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
Im CVE-Radar öffnen
↗ Quelle (ubuntu.com)
🗣️ Stimme:
It was discovered that the IPv6 implementation in the Linux kernel
contained a high rate of hash collisions in connection lookup table. A
remote attacker could use this to cause a denial of service (excessive CPU
consumption). (CVE-2023-1206)

Yu Hao and Weiteng Chen discovered that the Bluetooth HCI UART driver in
the Linux kernel contained a race condition, leading to a null pointer
dereference vulnerability. A local attacker could use this to cause a
denial of service (system crash). (CVE-2023-31083)

Ross Lagerwall discovered that the Xen netback backend driver in the Linux
kernel did not properly handle certain unusual packets from a
paravirtualized network frontend, leading to a buffer overflow. An attacker
in a guest VM could use this to cause a denial of service (host system
crash) or possibly execute arbitrary code. (CVE-2023-34319)

Lin Ma discovered that the Netlink Transformation (XFRM) subsystem in the
Linux kernel contained a null pointer dereference vulnerability in some
situations. A local privileged attacker could use this to cause a denial of
service (system crash). (CVE-2023-3772)

Kyle Zeng discovered that the networking stack implementation in the Linux
kernel did not properly validate skb object size in certain conditions. An
attacker could use this cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2023-42752)

Kyle Zeng discovered that the netfiler subsystem in the Linux kernel did
not properly calculate array offsets, leading to a out-of-bounds write
vulnerability. A local user could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-42753)

Kyle Zeng discovered that the IPv4 Resource Reservation Protocol (RSVP)
classifier implementation in the Linux kernel contained an out-of-bounds
read vulnerability. A local attacker could use this to cause a denial of
service (system crash). Please note that kernel packet classifier support
for RSVP has been removed to resolve this vulnerability. (CVE-2023-42755)

Bing-Jhong Billy Jheng discovered that the Unix domain socket
implementation in the Linux kernel contained a race condition in certain
situations, leading to a use-after-free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2023-4622)

Budimir Markovic discovered that the qdisc implementation in the Linux
kernel did not properly validate inner classes, leading to a use-after-free
vulnerability. A local user could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-4623)

Alex Birnberg discovered that the netfilter subsystem in the Linux kernel
did not properly validate register length, leading to an out-of- bounds
write vulnerability. A local attacker could possibly use this to cause a
denial of service (system crash). (CVE-2023-4881)

It was discovered that the Quick Fair Queueing scheduler implementation in
the Linux kernel did not properly handle network packets in certain
conditions, leading to a use after free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2023-4921)
Vollständiger Original-Artikel
Den kompletten Beitrag mit allen Details direkt auf ubuntu.com lesen.
↗ Original-Artikel auf ubuntu.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
HP Announces an AMD-Powered Portable Workstation
1 Quelle
Microsoft’s design lead says users “can feel” Windows 11 speeding up, confirms major improvements this fall
1 Quelle
What I Actually Learned Adding Asgardeo Login to a Side Project
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten USN-6439-1: Linux kernel vulnerabilities

Thematisch verwandte Begriffe: USN64391, Linux, kernel, vulnerabilities · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...