CVE-2023-46838
7.5
HIGH
CVSS 3.1
EPSS 1.2%
描述
Transmit requests in Xen's virtual network protocol can consist of multiple parts. While not really useful, except for the initial part any of them may be of zero length, i.e. carry no data at all. Besides a certain initial portion of the to be transferred data, these parts are directly translated into what Linux calls SKB fragments. Such converted request parts can, when for a particular SKB they are all of length zero, lead to a de-reference of NULL in core networking code.
如何修補 CVE-2023-46838
要修補 CVE-2023-46838,請將受影響套件升級到下列已修補版本。
- —升級至 5.15.147-r1 或更新版本
- —升級至 5.10.209-1 或更新版本
CVE-2023-46838 正在被利用嗎?
低 — EPSS 為 1.2%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 5.15.147-r1
- from 0, < 5.10.209-1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |