A NULL pointer dereference vulnerability was found in netlink_dump. This issue can occur when the Netlink socket receives the message(sendmsg) for the XFRM_MSG_GETSA, XFRM_MSG_GETPOLICY type message, and the DUMP flag is set and can cause a denial of service or possibly another unspecified impact. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is unlikely.
CVSS Details
- CVSS 3.1 Base Score: 6.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Jul 12, 2023 |
| Oracle_linux | — | Upgrade kernel-uek | Sep 1, 2023 | Jul 18, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 12, 2023 |
| Suse | — | Upgrade kernel-develUpgrade kernel-defaultUpgrade kernel-default-baseUpgrade kernel-sourceUpgrade kernel-symsUpgrade kernel-macrosUpgrade kernel-default-devel | Aug 17, 2023 | Jul 12, 2023 |
| Ubuntu | — | Upgrade linux-fipsUpgrade linuxUpgrade linux-lts-xenialUpgrade linux-kvmUpgrade linux-aws | Nov 19, 2024 | Jul 12, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub